Skip to content

Security: suriAI/suri

Security

SECURITY.md

Security Policy

Supported Versions

Attendance systems handle sensitive biometric data. Only the latest version of Suri is supported with security updates.

Version Supported
0.1.x
< 0.1.0

Reporting a Vulnerability

We/Authors take security seriously. If a vulnerability is discovered, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please send a detailed report via LinkedIn or open a "Draft Security Advisory" on GitHub if you have the permissions.

Response Time

Reports will be acknowledged within 48–72 hours. A fix will be prioritized based on the severity and impact on biometric privacy.

Biometric Privacy

Suri is designed with "Privacy by Default." If you find a way to extract raw face images or unencrypted embeddings from the local database or the sync stream, this is considered a High Severity issue.

There aren’t any published security advisories