Skip to content

Security: dodge1218/debi

Security

SECURITY.md

Security Policy

Scope

This repository is currently a local research pipeline. It does not run a server, accept remote user input, store credentials, or process private user data by design.

Security-sensitive areas:

  • source ingestion and table parsing
  • report generation
  • CI workflows
  • model-assisted extraction workflow
  • generated public artifacts

Reporting a Vulnerability

Please open a private security advisory on GitHub if available, or contact the repository owner through GitHub.

Do not include private credentials, unpublished proprietary source material, or personal health data in issues.

Data Safety

Do not commit:

  • API keys
  • private PDFs or datasets without redistribution rights
  • personally identifiable information
  • protected health information
  • unpublished lab data unless explicitly approved

Public Claims Safety

Security for this project includes claim safety. Public reports must not include:

  • unsupported disease-causation claims
  • claims of intent by named companies or vendors
  • unreviewed model output presented as evidence
  • numeric values without source or assumption lineage

There aren't any published security advisories