Skip to content

Security: DevMemory-AI/devmemoryai

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
v1.1.0 Yes
< v1.1.0 No

Reporting a Vulnerability

DevMemory AI runs 100% local-first and does not send data to any remote servers. However, if you discover a security issue in our local sandbox, filesystem isolation, or CLI/Dashboard API handlers, please report it immediately:

  1. Do NOT open a public GitHub issue.
  2. Email your findings directly to the core maintainer or submit a private security disclosure on GitHub.
  3. Include details about the vulnerability, step-by-step reproduction instructions, and proof of concept.

We will review reports and release patches promptly.

There aren't any published security advisories