Skip to content

Security: Papr-ai/memory-opensource

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

Please DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please email: security@papr.ai

Include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

What to Expect

  • We will acknowledge your email within 48 hours
  • We will provide an initial assessment within 5 business days
  • We will keep you updated on the progress
  • We will credit you in the security advisory (unless you prefer to remain anonymous)

Disclosure Policy

  • We aim to disclose vulnerabilities within 90 days of the report
  • Critical vulnerabilities will be patched and disclosed as soon as possible
  • We will coordinate with you on the disclosure timeline

Supported Versions

Version Supported
1.x
< 1.0

Security Best Practices

When self-hosting Papr Memory:

  • Always use HTTPS in production
  • Keep all dependencies up to date
  • Use strong passwords for databases
  • Regularly backup your data
  • Implement rate limiting
  • Monitor logs for suspicious activity
  • Use firewall rules to restrict access

Thank you for helping keep Papr Memory secure!

There aren’t any published security advisories