If you discover a security vulnerability in any Hardonian repository, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email security@aiautomatedsystems.ca with:
- A description of the vulnerability
- Steps to reproduce
- The affected repository and file(s)
- Potential impact assessment
We aim to acknowledge reports within 48 hours and provide a fix timeline within 7 days.
All repositories under the Hardonian GitHub organization are in scope.
| Repository | Supported Versions |
|---|---|
| Settler | Latest release |
| storefront | Latest main branch |
| Hardonian | Latest main branch |
We run automated weekly security audits across all repos using OpenCodeReview and custom security audit tooling. Audit reports are available at aiautomatedsystems.ca/security.
We do not currently offer a bug bounty program, but we credit reporters in our security advisories.