Skip to content

Security: zaber-dev/ai-prompt-simulation

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open public issues for security vulnerabilities.

Please report vulnerabilities privately to: security@zaber-dev.dev

Include:

  • affected version
  • reproduction steps
  • potential impact
  • suggested mitigation if available

Response Targets

  • acknowledgment: within 48 hours
  • triage: within 5 business days
  • fix timeline: based on severity and impact

Supported Versions

Version Supported
0.1.x Yes
<0.1.0 No

Security Best Practices

  • Never hardcode API keys.
  • Use environment variables for provider credentials.
  • Avoid storing sensitive prompt data in plaintext logs.
  • Review custom evaluators before production use.

There aren't any published security advisories