This repository accepts security reports for:
- Python package runtime and library surfaces (
src/zpe_neuro). - Repo-local verification and gate scripts (
tools/). - CI and release pipeline configurations.
Please report vulnerabilities privately to the project owner with:
- A clear impact summary.
- Reproduction steps or proof-of-concept.
- Affected versions/commit ranges.
- Suggested remediation when available.
Send reports to architects@zer0pa.ai.
- Initial acknowledgement: within 5 business days.
- Triage and severity classification: within 10 business days.
- Remediation timeline: shared after triage.
Public disclosure should be coordinated after a fix is available.