This is the default security policy for BaionSyS
repositories. A repository with its own SECURITY.md (e.g.
baion-vault-method)
follows its own, more specific policy.
Please do not open a public issue for a suspected vulnerability.
- Preferred: use GitHub private vulnerability reporting — the Security → Report a vulnerability tab on the affected repository. It is enabled on all BaionSyS repositories.
- Email: steven.mullinsjr@baion.dev with subject line
SECURITY: <repository>.
You will receive an acknowledgment within 72 hours. BAION Systems is a founder-operated organization; triage is done by the maintainer directly.
- Source code, workflows, and release artifacts in BaionSyS public repositories.
- The public demo at demo.baion.dev.
- Confirmed issues are fixed in a corrective release that preserves the affected version (superseded, not deleted), with the defect, the fix, and the regression test documented in the changelog — findings from external review are credited unless you prefer otherwise.
- No legal action against good-faith research that respects user data and service availability.