GoMyRO takes security reports seriously. Please do not open public GitHub issues, pull requests, or discussions for suspected vulnerabilities.
Report security issues privately by email:
TODO: Confirm this mailbox is active before publishing public repositories.
If email is not available, use the official private security or commercial support channel published by GoMyRO.
Please include as much relevant detail as possible:
- A clear description of the issue
- The affected repository, package, product, component, or deployment model
- Steps to reproduce or proof-of-concept details
- Potential impact and affected data or systems
- Relevant versions, configuration, logs, or screenshots
- Your preferred contact information for follow-up
Do not include customer data, production secrets, private keys, access tokens, or sensitive business information unless explicitly requested through a secure channel.
We ask security researchers and users to:
- Report vulnerabilities privately and give GoMyRO reasonable time to investigate.
- Avoid accessing, modifying, deleting, or exfiltrating data that is not yours.
- Avoid service disruption, destructive testing, social engineering, spam, or physical attacks.
- Keep vulnerability details confidential until GoMyRO has assessed and addressed the issue.
GoMyRO will review reports, prioritize remediation based on severity and impact, and communicate updates when appropriate.
TODO: Define supported public repositories, SDKs, connectors, tools, and product versions.
| Area | Supported status | Notes |
|---|---|---|
| Core GoMyRO platform | TODO | Commercial product; support scope to be defined. |
| Public SDKs | TODO | Define supported SDKs and versions. |
| Public connectors | TODO | Define supported connectors and versions. |
| Examples and documentation | TODO | Define support expectations. |