Skip to content

Security: ArcRouterAI/arcrouter

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

This package contains no authentication, no network calls, and no secrets handling — it is a pure local classifier.

If you find a security issue (e.g., a ReDoS vulnerability in a regex pattern), please report it at:

security@arcrouter.com

Include:

  • A description of the issue
  • Steps to reproduce
  • Potential impact

We will respond within 72 hours and aim to release a fix within 7 days.

Scope

ReDoS (Regular Expression Denial of Service) in any of the regex patterns is in scope and should be reported privately before disclosure.

There aren’t any published security advisories