Skip to content

Security: bdeeps/docforge

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
main Yes

Reporting a vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Email or DM the repository owner with:

  • Description of the issue
  • Steps to reproduce
  • Impact assessment
  • Suggested fix (if any)

We aim to respond within 72 hours.

Security practices

API keys

  • Agent api_key values (df_…) are shown once at registration
  • Keys are stored as SHA256 hashes in the database
  • Never commit keys to git, logs, or public issues

Document content

  • Uploaded documents may contain sensitive data
  • Run DocForge in a trusted network or with appropriate access controls
  • Configure DOCFORGE_MAX_UPLOAD_MB to limit upload size

Production deployment

  • Use HTTPS (Railway/custom domain)
  • Use PostgreSQL with Railway-managed credentials
  • Rotate agent API keys if compromised (re-register new agent identity)

Known considerations

  • MVP uses CREATE TABLE IF NOT EXISTS — no Alembic migrations yet
  • API key auth is optional for ingest endpoints (recommended for tracking)
  • CORS allows all origins by default — tighten for production if needed

There aren't any published security advisories