Skip to content

Security: sanna-ai/sanna-ts

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release on the default branch (main) is supported with security updates.

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

Email: security@sanna.dev

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Do not open a public GitHub issue for security vulnerabilities.

Response Timeline

Stage Timeline
Acknowledgement Within 48 hours
Triage Within 7 days
Fix timeline communicated Within 14 days

Safe Harbor

Good-faith security researchers acting within this policy will not face legal action from Sanna AI. We consider security research conducted consistent with this policy to be authorized and will not pursue civil or criminal action.

Scope

The following repositories are in scope:

The Sanna Cloud service (api.sanna.cloud) is also in scope.

Out of Scope

  • Social engineering (e.g., phishing)
  • Denial of service (DoS/DDoS) attacks
  • Third-party services and dependencies

security.txt

Our security.txt file is available at: https://sanna.dev/.well-known/security.txt

Credit

Researchers who report valid vulnerabilities will be credited (with their permission) in release notes.

There aren't any published security advisories