Skip to content

Security Policy ​

Aletheia is risk-decisioning infrastructure, so we treat security reports seriously.

Reporting a vulnerability ​

Email aletheia-dev@ajrd.net with:

  • a description of the issue and its impact,
  • steps to reproduce or a proof of concept,
  • the affected version: the platform release or image tag, or the npm package and its version.

Please do not disclose a security problem anywhere public before it is fixed. We aim to acknowledge reports within 3 business days and to publish a fix and an advisory once a patch is available. Please give us reasonable time to remediate before public disclosure.

Supported versions ​

The latest platform release and the latest version of each npm package receive security fixes.

Released under the Apache-2.0 License.