| Version | Supported |
|---|---|
| 0.25.x | ✅ |
| < 0.25 | ❌ |
If you discover a security vulnerability in Pyrite, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, use GitHub's private vulnerability reporting feature:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Provide a detailed description of the vulnerability
We will acknowledge receipt within 48 hours. For the supported configurations below, we aim to fix critical issues within 7 days.
Pyrite's supported security boundary today is one operator: you, your agents (with the MCP read/write/admin tiers), and people you trust with everything on the instance.
Running Pyrite for people who should not see each other's data — accounts with per-KB permissions, anonymous readers, the public /site, a shared server on the internet — is experimental. Those features exist and are being hardened release by release, and there are known open issues in how access between users and KBs is enforced. Until this notice is removed:
- Treat every KB on a shared instance as readable by every user of that instance.
- Keep genuinely private KBs on a separate instance, or local.
- Reports about isolation between users or KBs are welcome through the private channel above. They are fixed in regular releases, batched, rather than as emergency patch releases.
This policy applies to the pyrite Python package and its server components (REST API, MCP server).
- Never commit your
.envfile or API keys to version control - Use read-only KB configurations for untrusted data sources
- Run the REST API behind a reverse proxy in production
- Keep dependencies up to date