Skip to content

Security: ForgedEmir/Parralax

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

PARALLAX handles visual evidence and operational workflows. If you discover a security vulnerability, please report it privately.

Do not open a public issue. Send details to [email protected].

We will acknowledge receipt within 48 hours and provide an estimated timeline for a fix.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if applicable)

Scope

  • The PARALLAX engine (server/)
  • The MCP tool layer (server/mcp.ts)
  • The evidence ledger (server/engine.ts)
  • Vision model adapters (server/vision.ts)

Out of scope

  • Vulnerabilities in third-party dependencies (report to the respective maintainers)
  • Theoretical attacks requiring physical access to the server hardware

Safe harbor

We will not take legal action against researchers who report vulnerabilities in good faith and follow this policy.

There aren't any published security advisories