Security Policy
Last updated: May 22, 2026
Reporting a Vulnerability
We take the security of AiDotNet seriously. Please report security vulnerabilities through one of the channels below — never via public GitHub issues, discussions, or social media.
Preferred: GitHub Security Advisories
Report privately through theGitHub Security Advisory form. This is the fastest path and gives us a structured audit trail.
Alternative: Encrypted Email
Email admin@aidotnet.dev. We strongly recommend encrypting sensitive disclosures with our PGP key (available at docs/security/pgp.txtin the repository, or by request).
Response SLA
| Stage | Target |
|---|---|
| Acknowledge receipt | 5 business days |
| Triage + severity classification | 10 business days |
| Fix for SEV-1 (critical) | 30 days from triage |
| Fix for SEV-2 (high) | 60 days from triage |
| Fix for SEV-3 (medium) or lower | Next minor release |
Severity uses the CVSS 3.1calculator. We assign CVE identifiers via GitHub Security Advisories for any vulnerability rated SEV-2 or higher.
Embargo Policy
We follow a 90-day embargo from the date we acknowledge the report, or until a fix is publicly released — whichever is sooner. Reporters who prefer a shorter or longer embargo for coordinated disclosure should say so in their initial report. We will not unilaterally extend embargoes beyond 90 days without reporter agreement.
Supported Versions
Until AiDotNet reaches 1.0, supported versions are the two most recent minor releases:
- Latest minor: all security fixes
- Previous minor: SEV-1 and SEV-2 fixes only
- All older 0.x releases: upgrade required
After 1.0 ships, we will publish a long-term-support window and update this section.
Federal / Regulated Adoption
U.S. government, military, national laboratory, and other regulated deployments (FedRAMP, FISMA, NIST AI RMF / SP 800-218 SSDF, CMMC, HIPAA, SOC 2 Type II, ISO 27001) should contact admin@aidotnet.devfor our Enterprise security program. The Enterprise tier includes:
- Air-gapped deployment support (no telemetry, no license-server callout)
- FIPS 140-3 compatible cryptographic modules
- SBOM (CycloneDX 1.5) generation per release
- SLSA Level 3 build provenance attestations
- Signed NuGet packages
- Dedicated security contact + custom SLA
- NIST SP 800-218 SSDF compliance documentation
See /federal-usefor the federal-use page or/enterprisefor general enterprise terms.
Coordinated Disclosure & Credit
We credit reporters in our advisory text and in release notes unless the reporter requests anonymity. If you wish to publish your own write-up after the embargo ends, please share the draft with us at least 48 hours in advance so we can coordinate timing.
Escalation
If you have not received an acknowledgement within 5 business days, please escalate to admin@aidotnet.devwith subject [ESCALATION] Security report not acknowledged.