Skip to content

Security: Zoverions/OntarioEdAI

Security

.github/SECURITY.md

Security Policy

Supported Versions

OntarioEdAI follows a rolling-release model for the main branch.

Version Supported
0.4.x
< 0.4 ⚠️ Best effort

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Use one of the following channels:

  1. GitHub Security Advisory: Open a draft advisory for this repository.
  2. Email: Contact the maintainers at security@zoverions.com.

Scope

We are particularly interested in:

  • Sandbox Escapes: Any way to break out of the local execution environment.
  • Privacy Leaks: Unauthorized access to student data or PII.
  • Ledger Tampering: Methods to forge or alter local educational credentials.
  • P2P Security: Vulnerabilities in the offline mesh networking or WebRTC layers.

Response Process

  • Acknowledgement within 48-72 hours.
  • Triage and severity assessment within 7 days.
  • Coordinated disclosure after a fix is verified.

There aren't any published security advisories