Thank you for helping keep BindAI secure.
We take security issues seriously and appreciate responsible disclosure of vulnerabilities.
The following versions are currently supported with security updates.
| Version | Supported |
|---|---|
| Latest Release | ✅ |
| Previous Minor Release | ✅ |
| Older Releases | ❌ |
Please do not open public GitHub issues for security vulnerabilities.
Instead, report vulnerabilities privately.
You can:
- Open a private security advisory through GitHub.
When reporting a vulnerability, please include:
- A description of the issue
- Steps to reproduce
- Impact assessment
- Proof of concept (if available)
- Suggested mitigation (optional)
Our typical response timeline is:
- Acknowledgement: within 72 hours
- Initial assessment: within 7 days
- Resolution: depends on severity and complexity
If the issue is confirmed, we will:
- Investigate the report.
- Develop a fix.
- Publish a patched release.
- Credit the reporter (if desired).
Please avoid publicly disclosing vulnerabilities until a fix has been released.
Responsible disclosure helps protect users of BindAI.
This policy applies to:
- BindAI framework
- Official BindAI packages
- Official providers
- Documentation website
- GitHub repository
Third-party integrations are outside the scope of this policy unless explicitly maintained by the BindAI project.
When using BindAI:
- Never commit API keys or secrets.
- Store credentials in environment variables.
- Rotate compromised credentials immediately.
- Keep dependencies up to date.
- Validate untrusted inputs.
- Follow provider-specific security recommendations.
Thank you for helping make BindAI safer for everyone.