As an advocate for "Governance-as-Code" and an ISO 42001/27001 Lead Auditor, I take the security, privacy, and deterministic reliability of these AI governance prototypes very seriously. 作為「代碼即管治」的倡導者及 ISO 42001/27001 領先審計師,我極度重視這些 AI 管治原型的資訊安全、私隱保護及決定性可靠程度。
We encourage responsible reporting of any security flaws, including but not limited to: 我們鼓勵負責任地回報任何安全缺陷,包括但不限於:
- Data Leakage: Potential exposure of Personally Identifiable Information (PII) or sensitive audit logs. (個人資料或敏感審計日誌外洩)
- Guardrail Bypasses: Methods to bypass deterministic compliance constraints (e.g., Prompt Injections causing the system to accept out-of-scope tasks). (繞過決定性合規護欄的方法,例如提示詞注入)
- Architectural Vulnerabilities: Flaws in the local RAG indexing or vector database access controls. (本地 RAG 索引或向量資料庫存取控制漏洞)
DO NOT open a public issue for security vulnerabilities. Public disclosure before a patch is available puts enterprise governance systems at risk. 請勿在公開的 Issue 區塊提交安全漏洞。 在修補程式釋出前公開漏洞,將危及企業管治系統的安全。
Please report any security or compliance vulnerability privately via direct message on LinkedIn: 請透過 LinkedIn 訊息私下回報任何安全或合規漏洞: 👉 Jacky Law - LinkedIn
- You will receive an acknowledgment of your report within 72 hours. (您將於 72 小時內收到回報確認)
- We will provide a timeline for triage and remediation based on the severity of the identified risk. (我們將根據風險嚴重程度,提供分類與修復的時間表)