Skip to content

Security: jagmarques/asqav-compliance

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

Email info@asqav.com with details. We will respond within 48 hours.

Do not open public issues for security vulnerabilities.

Supported Versions

Only the latest published release is supported.

Scope

This repository contains asqav-compliance, a static and runtime scanner for AI agent compliance.

Report issues that affect:

  • Scanner rule evaluation and detection logic
  • Findings output format or injection into CI reports
  • Any path where scanner input can alter host system state
  • False-negative patterns that let known-bad code pass

Do not report general false positives through this channel. Use regular issues for rule tuning.

There aren't any published security advisories