Skip to content

Security: MORTEN-BUUR/nordef-matrix-open-control

SECURITY.md

Security Policy

Supported status

3.0.0-lab is a research candidate. It has no live executor and is not approved for production or customer use.

Reporting a vulnerability

Report security issues privately to the project maintainers. Do not include real credentials, private customer data, production endpoints, or weaponized exploit payloads.

A useful report contains:

  • affected version and component;
  • defensive reproduction summary;
  • impact and prerequisites;
  • proposed mitigation;
  • whether the issue can bypass execute=false, root verification, replay protection, input isolation, or evidence integrity.

Non-goals

This project does not authorize testing against systems you do not own or have permission to assess. It must not be used for credential theft, unauthorized scanning, exploitation, denial of service, persistence, evasion, or destructive action.

There aren't any published security advisories