+
Skip to content

Security: InfinitiBit/graphbit

Security

SECURITY.md

Security Policy

Overview

GraphBit is committed to maintaining security standards for our agentic framework. This document outlines procedures for reporting and handling security vulnerabilities.

Security Best Practices

  • API Keys: Use environment variables, never hardcode credentials
  • Updates: Keep GraphBit updated to the latest version
  • Environment: Use .env files for development, enterprise secret management for production

Reporting Security Vulnerabilities

⚠️ Important: If you discover a security vulnerability in GraphBit, please do not create a public issue.

How to Report

Option 1 - GitHub Security (Preferred):

  1. Navigate to the GraphBit repository
  2. Click the "Security" tab
  3. Click "Report a vulnerability"
  4. Fill out the private security advisory form

Option 2 - Email: info@graphbit.ai

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment
  • Affected versions

Response Timeline

  • 24 hours: Initial acknowledgment
  • 72 hours: Assessment and triage
  • 7 days: Response plan
  • 30 days: Patch development
  • Coordinated disclosure: After patch release

Guidelines

DO:

  • Report responsibly via email
  • Provide detailed reproduction steps
  • Allow time for coordinated disclosure

DON'T:

  • Publicly disclose before patches
  • Test on production systems
  • Access user data during research

Contact: info@graphbit.ai
Last Updated: July 2025

There aren’t any published security advisories

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载