This is the default security policy for the lyse-labs GitHub organization. Repositories with their own SECURITY.md (e.g. lyse) take precedence — check there first for repo-specific details (supported versions, trust boundaries).
If you discover a security vulnerability in any lyse-labs repository, please report it privately before disclosing publicly:
- GitHub Security Advisories: open a private advisory on the affected repository (e.g. https://github.com/lyse-labs/lyse/security/advisories/new) — preferred.
- Email: contact@getlyse.com. For PGP-encrypted reports, please request the key by email.
We aim to respond within 5 business days. Critical issues (RCE, data exfiltration, auth bypass) get a same-day acknowledgment.
This policy covers all repositories under the lyse-labs GitHub organization. Vulnerabilities in upstream dependencies should be reported to those projects directly.
Please do not open a public issue for security reports. We'll work with you on a coordinated disclosure timeline once the report is triaged.