Skip to content

Security: BindBrain/BindAI

Security

SECURITY.md

Security Policy

Thank you for helping keep BindAI secure.

We take security issues seriously and appreciate responsible disclosure of vulnerabilities.


Supported Versions

The following versions are currently supported with security updates.

Version Supported
Latest Release
Previous Minor Release
Older Releases

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Instead, report vulnerabilities privately.

You can:

  • Open a private security advisory through GitHub.

When reporting a vulnerability, please include:

  • A description of the issue
  • Steps to reproduce
  • Impact assessment
  • Proof of concept (if available)
  • Suggested mitigation (optional)

Response Process

Our typical response timeline is:

  • Acknowledgement: within 72 hours
  • Initial assessment: within 7 days
  • Resolution: depends on severity and complexity

If the issue is confirmed, we will:

  1. Investigate the report.
  2. Develop a fix.
  3. Publish a patched release.
  4. Credit the reporter (if desired).

Responsible Disclosure

Please avoid publicly disclosing vulnerabilities until a fix has been released.

Responsible disclosure helps protect users of BindAI.


Scope

This policy applies to:

  • BindAI framework
  • Official BindAI packages
  • Official providers
  • Documentation website
  • GitHub repository

Third-party integrations are outside the scope of this policy unless explicitly maintained by the BindAI project.


Security Best Practices

When using BindAI:

  • Never commit API keys or secrets.
  • Store credentials in environment variables.
  • Rotate compromised credentials immediately.
  • Keep dependencies up to date.
  • Validate untrusted inputs.
  • Follow provider-specific security recommendations.

Thank you for helping make BindAI safer for everyone.

There aren't any published security advisories