Skip to content

Security: Walxom/sec-research

Security

SECURITY.md

Security Policy

Supported Versions

SecResearch actively supports the latest release with security updates and bug fixes.

Version Supported
0.2.x
< 0.2.0

Reporting a Vulnerability

We take the security and integrity of SecResearch seriously. If you discover a potential security vulnerability, please report it responsibly:

  1. Private Disclosure: Do not open a public issue. Please submit a security report via GitHub Private Vulnerability Reporting or contact the maintainers directly.
  2. Details to Include:
    • Description of the vulnerability.
    • Steps to reproduce or proof-of-concept.
    • Potential impact and affected components (CLI, Extractor, FastMCP server, Storage).
  3. Response Timeline:
    • Initial acknowledgement: Within 48 hours.
    • Remediation and patch release: Prioritized based on severity.

Ethical Use & Academic Data Access

SecResearch only accesses public, peer-reviewed, open-access, and public-domain academic repositories (USENIX, NDSS, IACR, arXiv, NIST). It respects robots.txt, applies polite request rates, and never bypasses authentication mechanisms or paywalls.

There aren't any published security advisories