Skip to content

Security: XMECK-LAB/XMECK-AI

Security

SECURITY.md

Security

XMECK-AI public security wording is deliberately bounded.

Current engineering facts

  • ProjectGuard and authority/evidence mechanisms exist in the product architecture.
  • External-provider and side-effect paths are intended to remain explicit.
  • Product and package manifests are used to bind important artifact identities.
  • The current public candidate includes provenance, SBOM, recovery and evidence material.

Not claimed

This repository does not claim:

  • independent security certification;
  • regulatory/compliance certification;
  • universal provider/account qualification;
  • a trusted signed commercial installer.

Reporting

Do not publish credentials, tokens, private project data, recovery secrets, model credentials, or private evidence archives in public issues.

If GitHub private vulnerability reporting is enabled for this repository, prefer that channel for security-sensitive reports. Otherwise, disclose only enough public information to describe the issue without exposing secrets.

Supported public candidate

XMECK-AI 1.0.0.0 engineering Founder candidate:

XMECK-AI_FINAL_FOUNDER_CANDIDATE_1.0.0.0.zip

SHA-256:

0b3c346e2b9df7d8ee121f3451db0ef98ee340096a26b8f4a313cdbca44e1dd3

There aren't any published security advisories