Skip to content

Security: Chiaro-HQ/methodology

Security

SECURITY.md

Reporting a weakness

Some of our collection checks work by reading what a client's AI reports and refusing answers that read as shortcuts. The exact wording they match on is not published, because publishing it would publish the way around it.

If you find a way to defeat a check, or any weakness in the method that someone could exploit, please do not open a public issue. Write to cpa@chiarohq.com and we will respond quickly. Once it is fixed, we are glad to credit you in CHANGELOG.md.

Everything else, including hard criticism of the method, belongs in the open: see CONTRIBUTING.md.

There aren't any published security advisories