Skip to content

Security: norynta/release-notes

Security

SECURITY.md

Security policy

Reporting a vulnerability

Report suspected vulnerabilities privately to security@norynta.com. Do not open a public issue, discussion, or pull request for a security-sensitive report.

Include, when available:

  • the affected repository, package, endpoint, or deployed service
  • impact and the conditions required to reproduce it
  • minimal reproduction steps or a proof of concept
  • relevant request IDs, versions, or commit hashes
  • whether credentials, funds, signatures, or personal data may be exposed
  • a safe way to contact you for follow-up

Never send private keys, seed phrases, production access tokens, or unnecessary personal data. Redact secrets from logs and screenshots.

Supported versions

Norynta supports the current hosted service and the latest released version of each public SDK, Skill, and contract. Older versions may receive fixes when a safe backport is practical, but upgrading is the default remediation path.

Coordinated disclosure

Please allow time to confirm, remediate, deploy, and notify affected users before publishing details. Norynta will acknowledge good-faith reports and coordinate disclosure based on severity and operational risk.

There aren't any published security advisories