Skip to content

Security: MathGov/AIAP

Security

SECURITY.md

Security Policy

Scope

Security issues include defects that could permit false assurance, prompt compromise, identity substitution, covert assistance, evidence fabrication, status or formula fail-open behavior, unauthorized data access, retention failure, or public claims that exceed the evidence.

Reporting

Report vulnerabilities privately to james.mg@buv.edu.vn with:

  • affected version and artifact;
  • reproducible conditions;
  • likely consequence;
  • whether student, staff, institutional, or public claims are at risk;
  • a bounded remediation proposal; and
  • whether disclosure could enable immediate exploitation.

Do not publish live prompt banks, personal data, credentials, recordings, or step-by-step operational attack recipes. Coordinated disclosure should describe the failure class, affected scope, containment, correction, and requalification without increasing avoidable harm.

Status boundary

The included red-team and validation materials are reference instruments. They do not authorize testing against a live institution, student cohort, or system without explicit permission, ethics/governance review, and applicable legal authority.

There aren't any published security advisories