# Security Policy

## Reporting a Vulnerability

**Do NOT open a public GitHub issue for security vulnerabilities.**

Please report vulnerabilities by email to **support@agent-recon.net**. Include as much detail as
possible: affected component, reproduction steps, potential impact, and any suggested fixes.

A PGP key is available upon request for encrypted communication.

## Response Commitments

| Stage | Timeline |
|-------|----------|
| Acknowledge receipt | Within 24 hours |
| Triage and severity assessment | Within 72 hours |
| Coordinated disclosure window | 90 days from initial report |

Professional tier license holders receive priority triage for security reports.

## Scope

The following vulnerability classes are in scope:

- Remote code execution (RCE)
- SQL injection (SQLite)
- Credential exposure (API keys, license keys, secrets in logs)
- Authentication / authorization bypass
- Cross-site scripting (XSS) in the dashboard
- Hook script injection (malicious payloads via event data)
- WebSocket hijacking or unauthorized access
- SQLite database corruption via crafted events

## Out of Scope

- Social engineering attacks against maintainers or users
- Denial-of-service against the localhost-only service
- Issues requiring physical access to the machine
- UI cosmetic issues (layout, styling, typos)
- Vulnerabilities in third-party dependencies (please report these upstream to the relevant project)

## Coordinated Disclosure

We follow a 90-day coordinated disclosure policy:

1. Reporter sends vulnerability details to support@agent-recon.net.
2. We acknowledge within 24 hours and triage within 72 hours.
3. We work on a fix and coordinate a release timeline with the reporter.
4. After the fix is released (or after 90 days, whichever comes first), the reporter may publicly
   disclose the vulnerability.
5. We will credit the reporter in the release notes unless they prefer to remain anonymous.

## Credit

Reporters who follow this responsible disclosure process will be credited by name (or handle) in the
release notes for the version containing the fix. If you prefer anonymity, let us know in your
initial report.

## Related Documents

- [SECURITY-AUDIT.md](SECURITY-AUDIT.md) -- Security audit results and findings
- [SECURITY-RULES.md](SECURITY-RULES.md) -- Security rule definitions and classification
