Skip to content

Security: HawgAuto/drivetrain

Security

SECURITY.md

Security Policy

Drivetrain is intended for trusted local inference deployments. Do not expose it directly to the public internet without authentication, rate limiting, TLS termination, and a review of what upstream models and tools are reachable.

Sensitive data

Drivetrain is designed not to store raw prompts, messages, tool payloads, API keys, or Authorization headers in telemetry. If you modify telemetry fields, preserve that property and add tests.

Reporting issues

Please open a GitHub security advisory or private issue with reproduction steps and affected version/commit.

There aren't any published security advisories