Skip to content

Security: pctutu/ai-benchmark

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest published SADB V1 software release.

Reporting a Vulnerability

Use GitHub private vulnerability reporting for the repository. If that channel is unavailable, email support@pctutu.com. Do not open a public issue containing credentials, exploit details, or provider account information. Do not send live credentials by email.

Include the affected version, platform, impact, minimal reproduction, and any proposed mitigation. Remove API keys and personal data from all attachments.

The maintainers will acknowledge a valid report, investigate it, and coordinate disclosure through a patched release. Exact response times are not guaranteed.

Credential Model

SADB reads credentials from the SADB_API_KEY process environment variable. Results and standard logs must never contain the key. Users are responsible for clearing shell variables and protecting local batch configuration files.

SADB does not execute model output. A vulnerability that causes model output to be executed by a separate host application must also be reported to that host application's maintainers.

There aren't any published security advisories