Skip to content

Security: maurosandrini/venturerehearse

Security

SECURITY.md

Security policy

VentureRehearse is a local tool. The default backend runs fully offline and makes no network calls. The optional OpenAI backend sends your brief and the agents' state to the OpenAI API only when you explicitly choose --backend openai and set OPENAI_API_KEY.

Reporting a vulnerability

If you find a security issue (for example, a way the tool could leak an API key, or unsafe handling of a brief file), please do not open a public issue. Email the maintainer at msandrini@gmail.com with details and steps to reproduce. You can expect an acknowledgement within a few days.

Supported versions

This is alpha software (0.x). Security fixes are applied to the latest release only.

There aren't any published security advisories