Skip to content

Security: Winnux-OS/Tenvra

SECURITY.md

Security Policy

Supported Versions

No production release exists. Only the current default branch receives security fixes during the scaffold phase.

Reporting A Vulnerability

Do not open a public issue. Until a dedicated security address is configured, use a private GitHub security advisory in the official repository.

Include:

  • Affected component and revision.
  • Reproduction steps or proof of concept.
  • Expected impact.
  • Any suggested mitigation.

The project intends to acknowledge reports within three business days and provide an initial assessment within seven business days. These are targets, not contractual SLAs.

Scope

High-priority areas include authentication, authorization, signed job manifests, container isolation, update signing, node identity, model and dataset integrity, economic ledger invariants, and exposure of customer or contributor data.

Safe Harbor

Good-faith research that avoids privacy violations, service disruption, data destruction, financial harm, and public disclosure before remediation will be treated as authorized within the published testing scope.

Security Gates

No paid beta may launch with unresolved critical or high findings from the required independent review and penetration test.

There aren't any published security advisories