Skip to content

Security: lyse-labs/.github

Security

SECURITY.md

Security Policy — Lyse Labs

This is the default security policy for the lyse-labs GitHub organization. Repositories with their own SECURITY.md (e.g. lyse) take precedence — check there first for repo-specific details (supported versions, trust boundaries).

Reporting a vulnerability

If you discover a security vulnerability in any lyse-labs repository, please report it privately before disclosing publicly:

We aim to respond within 5 business days. Critical issues (RCE, data exfiltration, auth bypass) get a same-day acknowledgment.

Scope

This policy covers all repositories under the lyse-labs GitHub organization. Vulnerabilities in upstream dependencies should be reported to those projects directly.

Disclosure

Please do not open a public issue for security reports. We'll work with you on a coordinated disclosure timeline once the report is triaged.

There aren't any published security advisories