Security Policy

Hypertaks Founder Operating System - Maintained Release Line 4.5.x

Vulnerability Reporting Rule: Do not open a public GitHub issue for undisclosed security vulnerabilities. Public issues are reserved for general bugs, documentation, and non-sensitive support requests.

Supported Versions

Hypertaks maintains active security support for the current release line:

Version Supported Notes
4.5.x Yes Current maintained release line
< 4.5.0 No Legacy versions; upgrade recommended

Reporting a Vulnerability

We welcome responsible security disclosures. Please use one of the private reporting channels below:

When reporting a vulnerability, please include:

  1. Affected file(s), component, and version/commit hash.
  2. Step-by-step reproduction steps or minimal proof of concept.
  3. Observed impact and suggested remediation if available.

Response Timelines

Milestone Target Window
Initial Acknowledgement Within 3 business days
Triage and Assessment Within 7 business days
Fix or Mitigation Release Within 30 days (expedited for high-severity issues)
Coordinated Public Disclosure Mutually agreed upon prior to public release

Remote MCP Boundary

The remote Model Context Protocol adapter at https://hypertaks.crimsonriftstudio.com/mcp is strictly read-only. It exposes exactly four tools:

  1. hypertaks_manifest: returns product boundary, version, canonical public skills, and adapter limitations.
  2. hypertaks_get_skill: reads one canonical SKILL.md file by exact skill name.
  3. hypertaks_route: deterministically evaluates request text and selects the smallest canonical public skill entry point.
  4. hypertaks_verify_installation: verifies canonical skill entry files and brand assets with cryptographic SHA-256 evidence.

The remote MCP adapter has no filesystem mutation, file creation, file deletion, shell execution, or deployment capability on any client or host system.

Core Security Invariants