Skip to content

Security: runvendo/vendo

Security

SECURITY.md

Security Policy

Vendo renders agent-generated UI in a sandboxed iframe and executes tools against host APIs — security reports are taken seriously.

Reporting a vulnerability

Email security@vendo.run. Do not open a public issue. You'll get an acknowledgement within 48 hours.

Supported versions

The latest published minor version of each @vendoai/* package.

There aren't any published security advisories