Only the latest release on the default branch (main) is supported with security updates.
If you discover a security vulnerability, please report it responsibly:
Email: security@sanna.dev
Please include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
Do not open a public GitHub issue for security vulnerabilities.
| Stage | Timeline |
|---|---|
| Acknowledgement | Within 48 hours |
| Triage | Within 7 days |
| Fix timeline communicated | Within 14 days |
Good-faith security researchers acting within this policy will not face legal action from Sanna AI. We consider security research conducted consistent with this policy to be authorized and will not pursue civil or criminal action.
The following repositories are in scope:
The Sanna Cloud service (api.sanna.cloud) is also in scope.
- Social engineering (e.g., phishing)
- Denial of service (DoS/DDoS) attacks
- Third-party services and dependencies
Our security.txt file is available at:
https://sanna.dev/.well-known/security.txt
Researchers who report valid vulnerabilities will be credited (with their permission) in release notes.