Skip to content

Security: OffensiveSage/LLM-Observability-Audit

Security

SECURITY.md

Security Policy

🛡️ Reporting Vulnerabilities

Do not open public GitHub issues for security vulnerabilities.

Security was a primary focus during the development of this project. However, if you discover a vulnerability or a potential risk, please report it directly to me at:

📧 eshwar.desetty03@gmail.com

I will address any valid security concerns promptly.

🔐 Project Security Standards

1. Secrets Management

  • Strict Isolation: API keys (e.g., Groq, OpenAI) must never be committed to version control.
  • Environment Variables: All secrets are loaded exclusively from a local .env file.
  • Git Protection: The .gitignore file is configured to strictly exclude .env, *.key, and secrets/.
  • Key Rotation: In the event of an accidental commit, all exposed keys must be revoked and rotated immediately.

2. Data Privacy & Anonymization

  • No PII: This repository must not contain Personally Identifiable Information (PII).
  • Synthetic Data: Use only anonymized or synthetic datasets for testing (e.g., data/RA_Application_Task.csv).
  • Output Sanitization: Review all generated artifacts (logs, CSVs, HTML) for sensitive data before committing.

3. Dependency Security

  • Vulnerability Scanning: We utilize GitHub Actions to scan dependencies for known CVEs.
  • Minimal Footprint: Only essential, well-maintained packages are included in requirements.txt.

✅ Contributor Security Checklist

Before submitting a Pull Request, verify the following:

  • Secrets Check: No API keys or credentials are hardcoded.
  • Git Status: The .env file is untracked.
  • Data Review: No real user data is present in outputs.
  • Sanitization: Error messages and logs do not leak internal state or secrets.

🛡️ Secure Development Lifecycle (SDLC)

  1. Input Validation: Sanitize all external inputs before processing.
  2. Fail Safe: Ensure the application fails securely without exposing stack traces to end-users.
  3. Audit Trails: Maintain observability (via OpenTelemetry) without logging sensitive payloads.

There aren't any published security advisories