Responsible disclosure

Found something? Tell us privately first.

If you believe you have found a security issue in TekMyra (the gateway, the console, or the released package), please report it to us before discussing it in public, so that a fix can be ready by the time the problem is public.

How to report

There are two private channels, and either is fine: email support@tekmyra.ai, or GitHub’s private vulnerability reporting. That is the Report a vulnerability button on the repository’s Security tab, which opens a private advisory only the maintainers can see. Write it however is easiest for you; the details below just make it faster for us to reproduce.

  • What you observed The behaviour you saw and why you think it is a security problem rather than a bug.
  • How to reproduce it The smallest sequence of steps that shows it, plus the version of TekMyra you were running.
  • What you think the impact is Your own read on who is exposed and how. We may disagree, but it tells us where to look first.
  • How you would like to be credited A name, a handle, or not at all, whichever you prefer.

Please do not include real secrets If the issue involves prompt content, redact it. Describe the shape of the data, for example “an account number in the system prompt”, rather than pasting the real thing into an email.

What we commit to

TekMyra is an open-source project, and these are the same commitments the repository’s SECURITY.md makes, restated here.

We acknowledge

You get an acknowledgement within 3 working days and an assessment within 10 working days. If you do not hear back in that window, assume the message did not arrive and try the other channel. A report that silently failed to reach us is our failure, not yours.

We investigate

We try to reproduce it, tell you what we found, and say plainly if we conclude it is not a security issue and why.

We credit

If a fix ships because of your report, we credit you in the release notes in whatever form you asked for, including not at all.

We publish the fix

Security fixes land in the public repository under Apache-2.0 like any other change, with the issue described once it is safe to describe.

What we ask

  • Give us a chance to fix it Hold public disclosure until a fix is available, or until we have told you we cannot fix it and why. If we have not shipped a fix within 90 days of your report, you are free to publish. We would rather you publish than sit on it because we were slow.
  • Test against your own systems TekMyra runs on your infrastructure. Please do your testing there, not against anyone else's deployment.
  • Do not go after other people's data If you stumble into someone else's traffic or records, stop, and tell us that in the report.

Scope The gateway, the TekMyra Console, the released package, and this website. Issues in third-party model providers belong to those providers, though we are glad to be told about anything that affects how TekMyra interacts with them.