If you discover a security vulnerability in the OSSASAI framework, please report it responsibly:
- Do not open a public GitHub issue
- Email: https://github.com/gensecaihq/ossasai/security/advisories/new
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to address the issue.
This security policy covers:
- OSSASAI specification documents
- Control definitions and requirements
- Reference tooling and scripts
- Implementation guidance
For vulnerabilities in specific implementations (like OCSAS/OpenClaw), please report to the respective project maintainers.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
OSSASAI is built on established security principles:
- Defense in Depth - Multiple layers of controls
- Least Privilege - Minimal necessary access
- Fail Secure - Default to deny
- Complete Mediation - Verify every access
- Separation of Concerns - Distinct trust boundaries