chore(release): MIT license + CONTRIBUTING/SECURITY/CODE_OF_CONDUCT + README badges (S12)
This commit is contained in:
parent
0c42cebf90
commit
42f320bed1
6 changed files with 210 additions and 0 deletions
44
SECURITY.md
Normal file
44
SECURITY.md
Normal file
|
|
@ -0,0 +1,44 @@
|
|||
# Security Policy
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
We take security seriously. If you discover a security vulnerability, please report it responsibly.
|
||||
|
||||
**Please do NOT report security vulnerabilities through public issues.**
|
||||
|
||||
### How to Report
|
||||
|
||||
Email: hello@fromaitochitta.com
|
||||
|
||||
Include:
|
||||
- Description of the vulnerability
|
||||
- Steps to reproduce
|
||||
- Potential impact
|
||||
- Any suggested fixes (optional)
|
||||
|
||||
### What to Expect
|
||||
|
||||
- Acknowledgment within 48 hours
|
||||
- Regular updates on progress
|
||||
- Credit in the fix announcement (if desired)
|
||||
|
||||
## Supported Versions
|
||||
|
||||
| Version | Supported |
|
||||
| ------- | ------------------ |
|
||||
| latest | :white_check_mark: |
|
||||
| < latest| :x: |
|
||||
|
||||
## Security Best Practices
|
||||
|
||||
When using portfolio-optimiser-claude:
|
||||
- Keep dependencies updated
|
||||
- Keep your Claude API key in environment variables — never commit secrets
|
||||
- Follow the principle of least privilege for any data-source credentials
|
||||
|
||||
## Scope Note
|
||||
|
||||
portfolio-optimiser-claude is a **technical framework**. Deploying organizations own their own
|
||||
data protection, risk, and compliance assessments (DPIA/ROS). The framework ships technical
|
||||
prerequisites (provenance stamping, a mandatory deterministic validator, an offline-by-default
|
||||
test suite) but makes no compliance guarantees.
|
||||
Loading…
Add table
Add a link
Reference in a new issue