# Security Policy / Sicherheitsrichtlinie

## Execution Safety and Local-First Guarantees

`ellmos-homebase-mcp` is designed from the ground up as a **local-first, offline-capable** MCP stdio server with strict isolation and zero unexpected side-effects:

1. **Local-First & Offline Storage**: All memory, knowledge, persistent state, garden storage, routing statistics, connector queues, automation plans, and plugin registry entries are stored exclusively in local SQLite databases (default: `.homebase/`). No external cloud storage, telemetry, or remote tracking endpoints are contacted without explicit operator configuration.
2. **Credential-Free Routing & Discovery**: Model routing recommendations (`hb_route_*`), passive API discovery (`hb_api_*`), and plugin discovery (`hb_plug_*`) operate without requiring or exposing API tokens, private keys, or cloud credentials.
3. **No Autonomous Network Execution**: Connector queues (`hb_conn_*`) and automation chains (`hb_auto_*`) operate in plan-and-queue mode. They do not initiate unprompted network traffic or execute external code payloads autonomously.
4. **Fail-Closed Engine Seams**: In stack environments with canonical integration backends, any unreachable or unconfigured engine fails closed with a clear diagnostic tool error rather than silently falling back to unisolated storage.
5. **Data Protection & Secret Hygiene**: Example configuration files (`config/homebase.example.toml`) contain sanitized placeholders. Live configuration files (`homebase.toml`, `config/homebase.toml`, `*.local.toml`, `*.secret.toml`), database files, and private keys are strictly git-ignored and excluded from npm package distribution.

## Supported Versions

| Version | Supported | Notes |
|---|---|---|
| `0.1.0-alpha.x` | :white_check_mark: | Current active release branch |
| `< 0.1.0-alpha.1` | :x: | Legacy preview prototypes |

## Reporting a Vulnerability

If you discover a security issue, unintended network exposure, credential leak, or isolation bypass within `ellmos-homebase-mcp`, please report it privately:

- **Security Email**: `security@ellmos.ai`
- **Secondary Contact**: `security@open-bricks.org` / `support@lukasgeiger.com` / `lukas@open-bricks.org`
- **GitHub Advisory**: Use GitHub's private vulnerability reporting feature on the repository via [Security Advisories](https://github.com/ellmos-ai/ellmos-homebase-mcp/security/advisories).
- **Response SLA**: Initial triage and acknowledgment within **48 hours**. Detailed triage and remediation plan within 5 business days. Coordinated security patches are prioritized and released promptly.

Please do not disclose security issues publicly before a coordinated fix is available.

---

## Sicherheitsrichtlinie (Deutsch)

### Ausführungssicherheit und Local-First Garantien

`ellmos-homebase-mcp` ist von Grund auf als **lokal betriebener, offline-fähiger** MCP-Stdio-Server mit strikter Isolation und ohne unerwartete Seiteneffekte konzipiert:

1. **Local-First & Offline-Speicherung**: Alle Speicher-, Wissens-, Zustandseinträge, Wissensgarten-, Routingstatistiken, Konnektoren-Warteschlangen, Automationspläne und Plugin-Registereinträge verbleiben ausschließlich in lokalen SQLite-Datenbanken (Standard: `.homebase/`). Es werden keine externen Cloud-Speicher, Telemetrie- oder Tracking-Endpunkte kontaktiert.
2. **Schlüsselfreies Routing & passive Discovery**: Modell-Routing-Empfehlungen (`hb_route_*`), passive API-Erkundung (`hb_api_*`) und Plugin-Discovery (`hb_plug_*`) arbeiten ohne Erfordernis oder Weitergabe von API-Schlüsseln, Token oder Cloud-Zugangsdaten.
3. **Keine autonome Netzwerkausführung**: Konnektor-Warteschlangen (`hb_conn_*`) und Automationsketten (`hb_auto_*`) agieren im reinen Plan- und Warteschlangenmodus. Sie initiieren keine unaufgeforderten Netzwerkanfragen und führen keinen fremden Code unkontrolliert aus.
4. **Fail-Closed Engine-Schnittstellen**: In Stack-Umgebungen mit kanonischen Backends führt eine nicht erreichbare Engine zu einem klaren Diagnosefehler (Fail-Closed), anstatt stillschweigend auf unisolierte Speicher auszuweichen.
5. **Datenschutz & Geheimnis-Hygiene**: Konfigurationsbeispiele enthalten neutrale Platzhalter. Produktive Konfigurationsdateien, SQLite-Datenbanken und Schlüsseldateien sind über `.gitignore` und `.npmignore` vollständig von der Distribution ausgeschlossen.

### Unterstützte Versionen

| Version | Unterstützt | Anmerkungen |
|---|---|---|
| `0.1.0-alpha.x` | :white_check_mark: | Aktiver Entwicklungs- und Releasezweig |
| `< 0.1.0-alpha.1` | :x: | Frühere Vorschau-Prototypen |

### Melden von Schwachstellen

Sollten Sie eine Sicherheitslücke, unerwartete Datenübertragung oder einen Isolationsfehler entdecken, melden Sie diesen bitte vertraulich:

- **Sicherheits-E-Mail**: `security@ellmos.ai`
- **Sekundärkontakt**: `security@open-bricks.org` / `support@lukasgeiger.com` / `lukas@open-bricks.org`
- **GitHub Advisory**: Über die private Schwachstellenmeldung unter [Security Advisories](https://github.com/ellmos-ai/ellmos-homebase-mcp/security/advisories).
- **Reaktions-SLA**: Erstbewertung und Bestätigung innerhalb von **48 Stunden**. Detaillierte Einstufung und Behebungszeitplan innerhalb von 5 Werktagen. Sicherheitsrelevante Patches werden prioritär bereitgestellt.

Bitte veröffentlichen Sie Sicherheitsmeldungen nicht vor der Bereitstellung eines abgestimmten Fixes.
