Skip to content

Security: empathyethicist/trace

Security

SECURITY.md

Security Policy

TRACE processes potentially sensitive conversational evidence. Security issues that could affect evidence confidentiality, integrity, provenance, or auditability should be treated as high priority.

Report a vulnerability

Please report security issues privately to the maintainer before public disclosure.

Until a dedicated security contact channel is published, open a private GitHub security advisory if available for the repository, or contact the maintainer directly through the repository owner account.

Priority categories

Issues are particularly important if they affect:

  • chain-of-custody records
  • evidence-package integrity or hashing
  • audit-log tampering or omission
  • unintended transcript disclosure
  • provider credential leakage
  • incorrect or silent mutation of classified outputs

Disclosure guidance

  • Do not publish proof-of-concept details that expose live evidence or credentials.
  • Allow time for remediation and validation before public disclosure.

There aren't any published security advisories