Security Policy

Last updated: May 22, 2026

Reporting a Vulnerability

We take the security of AiDotNet seriously. Please report security vulnerabilities through one of the channels below — never via public GitHub issues, discussions, or social media.

Preferred: GitHub Security Advisories

Report privately through theGitHub Security Advisory form. This is the fastest path and gives us a structured audit trail.

Alternative: Encrypted Email

Email admin@aidotnet.dev. We strongly recommend encrypting sensitive disclosures with our PGP key (available at docs/security/pgp.txtin the repository, or by request).

Response SLA

StageTarget
Acknowledge receipt5 business days
Triage + severity classification10 business days
Fix for SEV-1 (critical)30 days from triage
Fix for SEV-2 (high)60 days from triage
Fix for SEV-3 (medium) or lowerNext minor release

Severity uses the CVSS 3.1calculator. We assign CVE identifiers via GitHub Security Advisories for any vulnerability rated SEV-2 or higher.

Embargo Policy

We follow a 90-day embargo from the date we acknowledge the report, or until a fix is publicly released — whichever is sooner. Reporters who prefer a shorter or longer embargo for coordinated disclosure should say so in their initial report. We will not unilaterally extend embargoes beyond 90 days without reporter agreement.

Supported Versions

Until AiDotNet reaches 1.0, supported versions are the two most recent minor releases:

  • Latest minor: all security fixes
  • Previous minor: SEV-1 and SEV-2 fixes only
  • All older 0.x releases: upgrade required

After 1.0 ships, we will publish a long-term-support window and update this section.

Federal / Regulated Adoption

U.S. government, military, national laboratory, and other regulated deployments (FedRAMP, FISMA, NIST AI RMF / SP 800-218 SSDF, CMMC, HIPAA, SOC 2 Type II, ISO 27001) should contact admin@aidotnet.devfor our Enterprise security program. The Enterprise tier includes:

  • Air-gapped deployment support (no telemetry, no license-server callout)
  • FIPS 140-3 compatible cryptographic modules
  • SBOM (CycloneDX 1.5) generation per release
  • SLSA Level 3 build provenance attestations
  • Signed NuGet packages
  • Dedicated security contact + custom SLA
  • NIST SP 800-218 SSDF compliance documentation

See /federal-usefor the federal-use page or/enterprisefor general enterprise terms.

Coordinated Disclosure & Credit

We credit reporters in our advisory text and in release notes unless the reporter requests anonymity. If you wish to publish your own write-up after the embargo ends, please share the draft with us at least 48 hours in advance so we can coordinate timing.

Escalation

If you have not received an acknowledgement within 5 business days, please escalate to admin@aidotnet.devwith subject [ESCALATION] Security report not acknowledged.