Skip to content

Security: jackylawck/ClauseDiff

Security

SECURITY.md

Security & Vulnerability Disclosure Policy (資訊安全與漏洞回報政策)

As an advocate for "Governance-as-Code" and an ISO 42001/27001 Lead Auditor, I take the security, privacy, and deterministic reliability of these AI governance prototypes very seriously. 作為「代碼即管治」的倡導者及 ISO 42001/27001 領先審計師,我極度重視這些 AI 管治原型的資訊安全、私隱保護及決定性可靠程度。

Scope of Security Concerns (安全關注範疇)

We encourage responsible reporting of any security flaws, including but not limited to: 我們鼓勵負責任地回報任何安全缺陷,包括但不限於:

  • Data Leakage: Potential exposure of Personally Identifiable Information (PII) or sensitive audit logs. (個人資料或敏感審計日誌外洩)
  • Guardrail Bypasses: Methods to bypass deterministic compliance constraints (e.g., Prompt Injections causing the system to accept out-of-scope tasks). (繞過決定性合規護欄的方法,例如提示詞注入)
  • Architectural Vulnerabilities: Flaws in the local RAG indexing or vector database access controls. (本地 RAG 索引或向量資料庫存取控制漏洞)

Reporting a Vulnerability (漏洞回報機制)

DO NOT open a public issue for security vulnerabilities. Public disclosure before a patch is available puts enterprise governance systems at risk. 請勿在公開的 Issue 區塊提交安全漏洞。 在修補程式釋出前公開漏洞,將危及企業管治系統的安全。

Please report any security or compliance vulnerability privately via direct message on LinkedIn: 請透過 LinkedIn 訊息私下回報任何安全或合規漏洞: 👉 Jacky Law - LinkedIn

Response SLA (服務回應承諾)

  • You will receive an acknowledgment of your report within 72 hours. (您將於 72 小時內收到回報確認)
  • We will provide a timeline for triage and remediation based on the severity of the identified risk. (我們將根據風險嚴重程度,提供分類與修復的時間表)

There aren't any published security advisories