We take security issues seriously and appreciate responsible disclosure.
Please do not open a public GitHub issue for security reports.
Report privately by email:
contact@abstractcore.ai
Include as much of the following as possible:
- A clear description of the issue and impact
- Reproduction steps or a minimal proof of concept
- Affected versions or commit hash
- Relevant logs, traces, prompts, or configuration
- Suggested mitigation, if you have one
If the issue is in an upstream dependency or model integration, it is still useful to report it so we can assess impact for AbstractMusic users.
We aim to acknowledge receipt within 3 business days and provide a status update within 7 business days.
This policy applies to vulnerabilities in this repository's code, packaging, and integrations.