Skip to the content.

Security Policy

Scope

This repository contains the AI IR Overlay™ framework: documentation, templates, and reference materials for AI agent incident response. It is not a runtime system or executable software.

The security boundary of this repository covers:

For incidents in your AI agent environments, the framework itself is the guide. Start with the Six Triage Questions.

Supported Versions

Version Supported with security fixes
Latest minor release (v0.35.x) ✅
Previous minor (v0.34.x) ✅ Critical fixes only
Older tags (≤ v0.33.x) ❌ Upgrade to latest
Pre-release / unreleased commits ❌

Reporting a Vulnerability

Please do not open a public GitHub Issue for security reports. Use one of the private channels below.

Preferred channel: GitHub Security Advisory

Open a private advisory: github.com/jacobideji/aiiroverlay/security/advisories/new

This is the fastest path. It gives you a private collaboration thread with the maintainer and lets us coordinate a fix and disclosure.

Alternative: direct contact

If a security advisory isn’t possible, contact the maintainer through jacobideji.com.

What to include

What to expect from us

Responsible Disclosure

We follow a coordinated disclosure model. Please give us a reasonable window (typically 30 days from acknowledgment for non-critical issues, faster for critical) before any public disclosure.

If you intend to publish research or a CVE, let us know your target date and we will work to meet it.

Out of Scope

Trademark and Brand Misuse

If you believe someone is misusing the AI IR Overlay™ or AI IR Overlay Certified™ word marks (for example, claiming “certification” status without authorization, or running a paid program under the name), please report it via jacobideji.com rather than the security advisory channel.