Skip to content

Security: poppycoderr/grounded-access

Security

SECURITY.md

Security Policy

Grounded Access is a reference system under active development. It has not been hardened for production use, and the demo identity setup (locally signed JWTs with a published demo key) is insecure by design.

The threat model lists what the system defends against, how each control is verified, and the risks it accepts.

Reporting a vulnerability

Please report vulnerabilities privately through GitHub security advisories rather than in public issues.

Reports that are especially valuable:

  • any way to retrieve, cite or infer the existence of content that the authorization model says should be hidden;
  • cross-tenant leakage through any endpoint, log, trace or metric;
  • sensitive text (queries, document content, prompts) appearing in telemetry.

Expect an acknowledgement within 7 days. Fixes land on main; there are no maintained release branches before v1.0.

There aren't any published security advisories