SIM-ONE Alpha coordinates model calls, local tools, connectors, credentials, protocols, approvals, memory, and user-controlled data. Security reports must be handled privately so users have time to protect their systems before details are made public.
| Version | Security support |
|---|---|
| 0.1.x Beta | Supported |
| Earlier development snapshots | Not supported |
Security fixes are made against the supported release line. Reproduce a report against the latest available 0.1.x release when possible.
Email contact@gorombo.com with the subject
[SIM-ONE Alpha Security] followed by a short description.
Do not disclose the issue in a public GitHub issue, pull request, discussion, log, screenshot, or other public channel. Do not include working credentials, private user data, or access tokens unless the maintainers explicitly request a secure transfer method.
Include:
The maintainers will:
Response and remediation time depend on severity, reproducibility, affected dependencies, and release complexity. This policy does not promise a fixed service-level agreement.
Use good-faith methods that avoid privacy violations, data destruction, service disruption, social engineering, credential theft, persistence, or access beyond what is necessary to demonstrate the issue. Stop testing and report the issue if you encounter private data or gain unintended access.
Reports about vulnerabilities in an upstream framework, library, or model should also follow that project’s disclosure process. Contact SIM-ONE Alpha maintainers when the dependency issue affects this product’s configuration, integration, or distributed release.
For non-security bugs, installation help, and usage questions, use Support.