Skip to content

Security: PaperStrange/TourGuideAI

SECURITY.md

TourGuideAI Security Policy

Supported Versions

We provide security updates for the following versions:

Version Supported
2.x.x
1.5.x
< 1.5

Reporting a Vulnerability

We take the security of TourGuideAI seriously. If you believe you've found a security vulnerability, please follow these steps:

  1. Do not disclose the vulnerability publicly
  2. Email security@tourguideai.com with details about the vulnerability
  3. Include the following information:
    • Type of vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • We will acknowledge receipt of your report within 48 hours
  • We will provide an initial assessment within 7 days
  • We aim to resolve critical issues within 30 days
  • We will keep you informed about our progress
  • After the issue is resolved, we will publicly acknowledge your responsible disclosure (unless you prefer to remain anonymous)

Security Measures

TourGuideAI implements the following security measures:

  • Regular security audits and penetration testing
  • Dependency vulnerability scanning in CI/CD pipeline
  • Static code analysis
  • OWASP compliance checks
  • Secret scanning
  • Software composition analysis (SCA)
  • Container security scanning

Security-related Configuration

Please ensure you follow our security best practices:

  1. Keep all dependencies up to date
  2. Enable MFA for all developer accounts
  3. Use environment-specific secrets and credentials
  4. Follow the principle of least privilege for all access controls
  5. Review security reports generated by our CI/CD pipeline

Learn More

For more information about security best practices, see the Technical Implementation section of our project lessons.

There aren’t any published security advisories