Skip to content

Security: sentientEddy/SHEPHERD-core

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a vulnerability, ethical concern, or misuse risk related to this project, please report it responsibly.

Email reports to:
eddy.projectvirgil@proton.me

We aim to respond to all security-related messages within 5 business days.

Please include as much relevant information as possible, including:

  • A clear description of the issue
  • Steps to reproduce (if applicable)
  • Potential impact
  • Any suggested mitigations

Scope

This project includes experimental tools designed to function in degraded, post-collapse environments. While we prioritize safety and ethical operation, SHEPHERD is provided as-is, without warranties or guarantees.

Known scope areas include:

  • Offline use of local AI models
  • Interaction with survival and ethical training datasets
  • Limited execution environments (Raspberry Pi, air-gapped systems, etc.)

Out of Scope

This project does not include:

  • Online data fetching
  • Remote telemetry
  • Centralized model governance

SHEPHERD is designed to be independently auditable and self-contained.

Responsible Use

Contributors and users are expected to uphold the core principles of the SHEPHERD system:

  • Do no harm
  • Preserve human dignity
  • Encourage ethical survival
  • Remain transparent and teachable

If any use of this system violates those principles, it is considered misuse.

Thank you for helping us keep SHEPHERD safe and aligned.

There aren’t any published security advisories