- Apache-2.0, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, issue templates - FastAPI app with /api/v1 healthz/readyz/system-status (honest AI disclosure) - Full SQLAlchemy schema (users, devices, refresh tokens, recordings, assets, upload sessions, transcripts, summaries, tags, jobs, exports) + Alembic migrations incl. Postgres FTS tsvector columns - Settings via SHONAR_* env only; local + S3 storage abstraction with path-traversal-safe keys - Docker dev compose (postgres+redis, 127.0.0.1-only); CI workflow; scripts - shared/openapi.json contract generated from app
23 lines
679 B
Markdown
23 lines
679 B
Markdown
# Security Policy
|
|
|
|
**Do not open public issues for security problems.** Email the maintainers
|
|
directly (see README contact). We aim to acknowledge within 72 hours.
|
|
|
|
## Scope
|
|
|
|
- Authentication / authorization bypass
|
|
- Data leakage between users
|
|
- Path traversal / unauthorized file access
|
|
- Injection (SQL, command, template)
|
|
- Secrets exposure in API responses
|
|
|
|
## Out of scope
|
|
|
|
- Physical device access
|
|
- Social engineering
|
|
- Vulnerabilities in optional third-party AI providers you configure
|
|
|
|
## What this project guarantees
|
|
|
|
See `docs/security.md` for the honest security model, including what is NOT
|
|
implemented (at-rest encryption is documented but not enabled by default).
|