D2b: llms.txt i rota - H1, blockquote, EN startkommando byte-identisk med README-ens forste kodeblokk (verifisert med diff), Docs- og Optional-seksjoner med relative fillenker. Loser README-ens tre konkurrerende startverb ved a velge den dokumenterte veien. Minimal med vilje: llms.txt er en konvensjon, ikke en ratifisert standard. Begrunnes IKKE med crawlere - leseren er en KI-agent som allerede star i repoet. D6: SECURITY.md sin kontaktadresse hello@ -> security@fromaitochitta.com. Kun sikkerhetskontakten; hello@ i CODE_OF_CONDUCT.md star urort (riktig for alt annet). shared/SECURITY.md er urort - shared/ er pull-only subtree fra commons og eies der. I samme okt (operator-ja 21.08): docs/extending.md sa "no bundled example ships a cost-baseline.json (checked)". Usant siden 09.08 - MALT: veglys-fv-soer og tunnel-hauglia shipper begge fila. Setningen peker na pa den shippede fila som formreferanse og gjengir ir.CostBaseline korrekt (project_id + items-map). llms.txt ligger utenfor _LIVE_DOCS-gaten (den skanner README.md + docs/**/*.md), verifisert i testfila - ingen ny doc-klassifisering kreves. Handover-gatens _REQUIRED_MEMBERS er en tilstedevaerelses-sjekk, ikke en uttommende liste. 874 passed / 5 skipped, uendret. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DA6HAF8HFQxGYC2h6ypRQe
2.6 KiB
Security Policy
Reporting a Vulnerability
We take security seriously. If you discover a security vulnerability, please report it responsibly.
Please do NOT report security vulnerabilities through public issues.
How to Report
Email: security@fromaitochitta.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
What to Expect
- Acknowledgment within 48 hours
- Regular updates on progress
- Credit in the fix announcement (if desired)
Supported Versions
Support follows the tags, not a calendar, and the table is deliberately version-free — a release number written here would drift the moment the next tag lands.
| Version | Security fixes | What that means |
|---|---|---|
| Newest tagged release | ✅ best-effort | Fixes land on main and ship in the next tag |
| Every earlier tag | ❌ | Earlier tags are never re-released. Upgrade, or fork and patch |
There is no long-term-support branch and no backporting. One maintainer, best-effort.
Deprecation Notice Period
When a supported surface is removed, or a dependency stops receiving security fixes:
- The deprecation is announced in
CHANGELOG.mdunder the release that introduces it, and repeated in the release notes on the forge. - At least one minor release — and no fewer than 30 days — passes between that announcement and the removal, so anyone reading the changelog has a version to move to before the old one goes.
- The stated exception is a security-critical removal. If leaving a surface in place is itself the risk, it goes in the next release and the changelog says plainly why the notice period was not used. This has not happened so far.
This is a notice period, not an SLA. See the organisation governance for what this project does and does not promise.
Security Best Practices
When using portfolio-optimiser:
- Keep dependencies updated
- Use environment variables for sensitive configuration — never commit secrets
- Prefer the local-only backend profile; the framework makes no silent network egress
- Follow the principle of least privilege for any data-source credentials
Scope Note
portfolio-optimiser is a technical framework. Deploying organizations own their own data protection, risk, and compliance assessments (DPIA/ROS). The framework ships technical prerequisites (local-only mode, provenance, no silent egress) but makes no compliance guarantees.