Skip to content

Security: CaliCastle/cali.so

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the version deployed at cali.so. The current v3 release is supported on main; unreleased integration work is supported while it remains on active dev or pull-request branches.

Report a vulnerability privately

Use GitHub's Security tab and choose Report a vulnerability. Do not open a public issue, discussion, or pull request for a suspected vulnerability, and do not include exploit details in public project updates.

Please include the affected surface, a minimal reproduction, impact, and any suggested mitigation. Remove credentials, personal data, private content, payment data, meeting details, and raw provider payloads from the report. If a demonstration needs sensitive evidence, describe how to reproduce it without attaching live data.

Coordinated disclosure

Please allow time to investigate, remediate, deploy, and notify affected users before publishing details. We will coordinate a disclosure date with the reporter when public disclosure is appropriate. We may ask that details remain private longer when a fix depends on an upstream provider or a safe migration.

Good-faith research should avoid privacy violations, service disruption, social engineering, persistent access, data destruction, and access beyond the minimum needed to demonstrate the issue. If you encounter user data or a live credential, stop and report it privately.

There aren't any published security advisories