# Security Policy Security matters in Raven ecosystem projects because the work touches AI infrastructure, biological workflows, and healthcare-adjacent systems. ## Reporting a vulnerability Please do **not** open a public issue for security reports. Email: bclerjuste@gmail.com Include: - Affected repository and commit/version. - Reproduction steps or proof of concept. - Impact assessment. - Suggested remediation if known. ## Scope Security-sensitive areas include: - Authentication and tenant isolation. - Consent and PHI handling. - Audit/provenance integrity. - Model registry and artifact signing. - Prompt/tool injection boundaries. - Secrets, tokens, and deployment configuration. ## Maintainer response The maintainer will acknowledge credible reports, prioritize fixes based on impact, and publish remediation notes when appropriate.