Open-Chat is beta software. The project has not been fully
security-audited, and we do not guarantee security updates for any
specific version or release. You use this software at your own risk. See
NOTICE for the licensing and component status.
Please report security issues or hardening proposals by email to:
Please do not open a public GitHub issue for a suspected vulnerability.
Due to the volume of reports and the significant share of LLM-assisted contributions in this project, we cannot review every report immediately. Each report is handled individually and may take time to triage.
There is no official bug-bounty program. However, very high impact and directly exploitable vulnerabilities may still be rewarded on a per-report basis, at our sole discretion.
Where a report can be verified, we intend to publish an audit log and document the resolution of the vulnerability. There is no formal disclosure process established yet; we plan to define one in the future.
Because the project is in beta, no version receives guaranteed security updates.
| Version | Security updates |
|---|---|
| Any / beta | None guaranteed |
This policy applies to the source code in this repository. Private
(proprietary) components and integrations described in NOTICE
are excluded from the public grant and are handled separately.