SECURITY POLICY
Coordinated Vulnerability Disclosure & Policy
Security is fundamental to Kronumos. We engineer deterministic program repair tools designed to synthesize verified software fixes while safeguarding system integrity, confidential IP, and operational environments.
1. Supported Versions
Security updates and critical vulnerability patches are actively evaluated and deployed for the following release targets:
| Release Version | Active Support | Deployment Target |
|---|---|---|
| v1.0.x Stable | Supported | Active (Ollama Hub / HF) |
| Development (main) | Supported | Rolling Canary |
2. Reporting a Security Vulnerability
If you identify a security vulnerability in Kronumos, the Edge Gateway, or the native Rust compiler Sub-Cortex, please report it responsibly through private channels.
Important: Do not open public GitHub issues or discussions for unpatched security vulnerabilities.
Direct all vulnerability disclosures to the security desk:
daffa@kronumos.com
Please include the following details in your report:
- Type and classification of vulnerability (e.g. sandbox escape, path traversal, rate-limit bypass, prompt injection).
- Step-by-step reproduction instructions or standalone proof-of-concept (PoC).
- Affected component, version tag, and operating system environment.
- Estimated blast radius and impact assessment.
3. Vulnerability Response Timeline
24 Hours
Initial Acknowledgment
48 Hours
Triage & Assessment
72 Hours
Remediation & Hotfix
4. Security Architecture Invariants
1. Path Traversal & Workspace IsolationStrict path verification routines ensure file operations remain strictly bounded inside user-authorized workspaces.
2. Sensitive Credential BlacklistingAutomatic blocking of sensitive credential stores, private keys, SSH directories, and cloud configuration files.
3. Dual-Layer Secret RedactionClient-side regex scrubbing coupled with edge masks scrub AWS keys, GitHub tokens, JWTs, and private keys before inference dispatch.
4. Cryptographic Binary IntegrityPre-compiled release binaries and installer scripts enforce SHA256 cryptographic checksum validation.
5. In-Memory Ephemeral ExecutionZero persistent disk logging of user source code or inference prompts across the system.
