The full security policy for knowledge-rag lives at the repository root:
This file exists so GitHub's automatic "Report a vulnerability" link — which searches .github/SECURITY.md first — always resolves to the canonical policy. Do not duplicate content here; the root SECURITY.md is the single source of truth.
- Report privately (preferred): https://github.com/lyonzin/knowledge-rag/security/advisories/new
- Email: lyonzin@users.noreply.github.com
- Response SLA: 48 hours acknowledgement, 90-day coordinated disclosure — see SECURITY.md § What to expect
- Threat model: SECURITY.md § Threat Model
- OpenSSF Best Practices self-assessment: openssf-best-practices.md