Skip to content

Security: rivenai/.github

SECURITY.md

Security Policy

The Riven AI team takes security issues seriously. We appreciate responsible disclosure of vulnerabilities affecting any repository in this organization.

Supported Versions

We support the latest released version of each Riven AI product. Older releases may receive critical security fixes at our discretion.

Reporting a Vulnerability

Please report security vulnerabilities by email to security@riven.ai.

Do NOT open public GitHub issues, pull requests, or discussions for security reports. Public disclosure before a fix is available puts users at risk.

When reporting, please include:

  • A description of the vulnerability and its impact
  • Steps to reproduce, including affected repository, version, and commit SHA if known
  • Any proof-of-concept code or screenshots (do not include real customer data)
  • Your contact information and whether you want public credit

What to Expect

  • Acknowledgement within 2 business days
  • Initial assessment within 5 business days
  • Status updates at least every 7 days until resolution
  • Coordinated disclosure — we will agree on a public disclosure timeline with you before publishing

Scope

In scope: any repository under the rivenai GitHub organization, the Riven AI platform services, and our deployed product surfaces.

Out of scope: third-party services we integrate with, social engineering of staff, denial-of-service testing against production, and any testing that affects real customer data.

Safe Harbor

If you make a good-faith effort to comply with this policy, we will not pursue legal action against you for your research. We will work with you to understand and resolve the issue quickly.

There aren't any published security advisories