SECURITY

Vulnerability disclosure, scope, and data practices. widemem is Apache 2.0 and source-available, so every claim on this page is auditable in the repository.

Reporting a vulnerability

If you find a security issue in widemem, do not open a public GitHub issue. Email the details to radu@cioplea.com with:

You should receive a response within 48 hours. I will work with you to understand the issue and coordinate a fix before any public disclosure.

Supported versions

Security patches are issued for the latest minor version of widemem. Older versions receive fixes only for critical issues. The authoritative version list is in the repository SECURITY.md.

Scope

widemem is a library, not a service. Security concerns include:

Data practices

Compliance stance

widemem is not itself SOC2 or HIPAA certified. It is a library you embed into a service whose compliance posture you control. The library gives you the building blocks (local storage, configurable retention, full audit trail, local-only LLM and embedding options). Teams that need dedicated help with a compliance review can start at the enterprise page.

Canonical source

The formal security policy lives in the repository as SECURITY.md. If this page and that file ever disagree, the file in the repository is authoritative.