- Apache-2.0, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, issue templates - FastAPI app with /api/v1 healthz/readyz/system-status (honest AI disclosure) - Full SQLAlchemy schema (users, devices, refresh tokens, recordings, assets, upload sessions, transcripts, summaries, tags, jobs, exports) + Alembic migrations incl. Postgres FTS tsvector columns - Settings via SHONAR_* env only; local + S3 storage abstraction with path-traversal-safe keys - Docker dev compose (postgres+redis, 127.0.0.1-only); CI workflow; scripts - shared/openapi.json contract generated from app
679 B
679 B
Security Policy
Do not open public issues for security problems. Email the maintainers directly (see README contact). We aim to acknowledge within 72 hours.
Scope
- Authentication / authorization bypass
- Data leakage between users
- Path traversal / unauthorized file access
- Injection (SQL, command, template)
- Secrets exposure in API responses
Out of scope
- Physical device access
- Social engineering
- Vulnerabilities in optional third-party AI providers you configure
What this project guarantees
See docs/security.md for the honest security model, including what is NOT
implemented (at-rest encryption is documented but not enabled by default).