Skip to content

Security: Zer0pa/ZPE-Mental

SECURITY.md

Security Policy

Supported Scope

This repository accepts security reports for:

  1. Python package runtime and public API (zpe_mental/).
  2. Rust-native extension and the Python/Rust boundary (src/lib.rs, Cargo.toml, pyproject.toml).
  3. Packaging, install, and release configuration committed in this repository.

Reporting

Please report vulnerabilities privately to architects@zer0pa.ai with:

  1. A clear impact summary.
  2. Reproduction steps or proof-of-concept.
  3. Affected versions or commit ranges.
  4. Suggested remediation when available.

If you need a private handoff channel beyond email, request it in the initial report. Do not post secrets, private keys, or live exploit payloads in a public issue.

Response Targets

  1. Initial acknowledgement: within 5 business days.
  2. Triage and severity classification: within 10 business days.
  3. Remediation timeline: shared after triage.

Public disclosure should be coordinated after a fix is available.

There aren't any published security advisories