Security

Report vulnerabilities privately.

For the public RuleOak open-source repository, use GitHub private vulnerability reporting and follow the repository SECURITY.md.

Responsible disclosure guidance

Security claims

Internal source checks, tests and hardening are evidence, not independent certification. Public claims should distinguish source-level qualification from third-party audit, deployment controls and operating-environment evidence.

Website package

This static website package contains no analytics, account system, advertising SDK or tracking script. Hosting-provider logs and controls remain deployment-environment concerns.