Please do NOT open a public GitHub Issue for security vulnerabilities.
If you discover a security-related vulnerability in Shield, please email us at security@noumenadigital.com with as much detail as possible.
When reporting a vulnerability, please provide:
- Description: A clear explanation of the security issue
- Proof-of-Concept (PoC): Steps to reproduce or a working example
- Affected Version(s): Which version(s) of Shield are impacted
- Impact Assessment: Potential consequences and affected use cases
- Suggested Fix (optional): If you have a proposed solution
We ask that you follow Responsible Disclosure guidelines and allow us time to develop and release a patch before publicly discussing the vulnerability. We typically request a grace period of 90 days from initial report to public disclosure.
When deploying Shield:
- Keep the gateway updated to the latest version
- Use MCP over HTTPS in production environments
- Restrict network access to the gateway using firewall rules
- Configure authentication and authorization policies (Rego-based policy evaluation)
- Monitor audit logs for suspicious activity
- Rotate credentials and tokens regularly