Skip to the content.

Security Policy

Scope

This repository contains the AI IR Overlay™ framework: documentation, templates, and reference materials for AI agent incident response. It is not a runtime system or executable software.

The security boundary of this repository covers:

For incidents in your AI agent environments, the framework itself is the guide. Start with the Six Triage Questions.

Supported Versions

Version Supported with security fixes
Latest minor release (v0.6.x)
Previous minor (v0.5.x) ✅ Critical fixes only
Older tags (≤ v0.4.x) ❌ Upgrade to latest
Pre-release / unreleased commits

Reporting a Vulnerability

Please do not open a public GitHub Issue for security reports. Use one of the private channels below.

Preferred channel: GitHub Security Advisory

Open a private advisory: github.com/jacobideji/aiiroverlay/security/advisories/new

This is the fastest path. It gives you a private collaboration thread with the maintainer and lets us coordinate a fix and disclosure.

Alternative: direct contact

If a security advisory isn’t possible, contact the maintainer through jacobideji.com.

What to include

What to expect from us

Responsible Disclosure

We follow a coordinated disclosure model. Please give us a reasonable window (typically 30 days from acknowledgment for non-critical issues, faster for critical) before any public disclosure.

If you intend to publish research or a CVE, let us know your target date and we will work to meet it.

Out of Scope

Trademark and Brand Misuse

If you believe someone is misusing the AI IR Overlay™ or AI IR Overlay Certified™ word marks (for example, claiming “certification” status without authorization, or running a paid program under the name), please report it via jacobideji.com rather than the security advisory channel.