S.H.O.N.A.R./SECURITY.md
avi 5fab96e824 M0: repo scaffold, backend skeleton, schema + migrations, dev compose, docs
- Apache-2.0, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, issue templates
- FastAPI app with /api/v1 healthz/readyz/system-status (honest AI disclosure)
- Full SQLAlchemy schema (users, devices, refresh tokens, recordings, assets,
  upload sessions, transcripts, summaries, tags, jobs, exports) + Alembic
  migrations incl. Postgres FTS tsvector columns
- Settings via SHONAR_* env only; local + S3 storage abstraction with
  path-traversal-safe keys
- Docker dev compose (postgres+redis, 127.0.0.1-only); CI workflow; scripts
- shared/openapi.json contract generated from app
2026-09-08 13:23:45 -05:00

679 B

Security Policy

Do not open public issues for security problems. Email the maintainers directly (see README contact). We aim to acknowledge within 72 hours.

Scope

  • Authentication / authorization bypass
  • Data leakage between users
  • Path traversal / unauthorized file access
  • Injection (SQL, command, template)
  • Secrets exposure in API responses

Out of scope

  • Physical device access
  • Social engineering
  • Vulnerabilities in optional third-party AI providers you configure

What this project guarantees

See docs/security.md for the honest security model, including what is NOT implemented (at-rest encryption is documented but not enabled by default).