Skip to content / 跳到正文

SECURITY REPORTS

Report a security issue

Identify the affected project, then choose the appropriate reporting channel. For high-impact issues, start with a private channel. Public discussions should contain sanitized information only.

security@teloa.ai

Baseline assessment tool

For vulnerabilities in the tool, such as cross-site scripting, imported-file handling, or assessment data leakage, use a private GitHub vulnerability report or email security@teloa.ai. Suggestions and disagreements about baseline requirements belong in ordinary public issues.

Teloa Community

By default, report sanitized security concerns and public evidence in a public issue. For remote code execution, large-scale credential leakage, or access to user privacy, start with private email and use the fixed-field template in the project’s SECURITY.md.

Marketplace and ecosystem projects

Identify the resource, source, version, and repository involved. Do not include live credentials, private user data, or directly exploitable payloads in public reports. Provide sensitive details through email.

What to include

  • Affected product, resource, version, or commit.
  • Expected behavior, actual behavior, and minimal sanitized reproduction steps.
  • Impact, affected components, and your severity assessment.
  • A contact for follow-up, and whether you prefer anonymous credit.

Supported versions and response commitments are defined by each project’s security policy.

← Back to Teloa AI Security

This security portal uses Cloudflare for visit and performance statistics. Assessment content stays in your browser and is not sent to analytics.