Skip to content

Security: AnnotateIt-AI/annotateit-python

Security

SECURITY.md

Security policy

This policy applies to all repositories in the AnnotateIt-AI organization and to the AnnotateIt application, website and web app. The full security overview is available at annotateit.ai/legal/security.

Reporting a vulnerability

Please do not report security vulnerabilities through GitHub Issues, Discussions, pull requests, or any other public channel.

Report vulnerabilities by email to umno.annotateit@gmail.com, and clearly mark the subject line as a security report.

Please include:

  • The affected platform and version (Windows, macOS, iPhone/iPad, or web app)
  • The affected surface (for example, annotator, dataset import/export or local REST API)
  • The impact of the issue as you understand it
  • Steps to reproduce
  • A minimal proof of concept, if available

Handling sensitive material

  • Do not include private datasets, user images, annotations, API keys, access tokens, licence data or personal information in a report.
  • If demonstrating the issue requires sensitive material, contact us first at umno.annotateit@gmail.com to agree on a safe way to share it.

Testing guidelines

When researching a potential vulnerability:

  • Do not perform destructive testing.
  • Do not violate the privacy of any user.
  • Do not access, modify, or affect devices or data that are not your own.

Scope note

The repositories in this GitHub organization contain the organization profile, community issue tracker, public product documents and policies. They do not contain the AnnotateIt application source code, so issues found in these repositories are unlikely to reflect the security of the application itself. Application vulnerabilities should still be reported to umno.annotateit@gmail.com.

There aren't any published security advisories