Policy Draft

Security Policy Draft

Rendered from the repo policy source as a real command-center page. Draft for review, not legal advice.

NyrA Swarm Little Buddy Security Policy Draft

Status: Draft for attorney review and release review

Last updated: 2026-05-31

Scope: NyrA Swarm Little Buddy desktop app only

Supported Versions

Version Status
0.1.0-alpha.76 Internal alpha only
0.1.0-beta.1 Planned paid beta

Do not publish a paid public release until a signed or trusted installer path, release notes, checksum policy, support inbox, and vulnerability intake process exist.

Security Contact

Security reports should go to nyrasupport@gmail.com after the user creates/confirms the inbox. Do not publish this address as a security contact until it is monitored.

Reports should include:

Do not send passwords, full card numbers, bank account numbers, raw API keys, full EIN/SSN, recovery codes, or unredacted private documents.

Vulnerability Testing Rules

Allowed after written approval:

Not allowed without explicit written authorization:

No bug bounty is promised unless a separate bounty program is published.

Implemented Security Controls

Current implemented controls include:

Required Before Paid Beta

Incident Response Draft

  1. Triage report and confirm affected version.
  2. Preserve relevant logs without collecting extra sensitive data.
  3. Reproduce in a clean test environment.
  4. Classify severity: billing/license, consent/privacy, computer control, data exposure, remote execution, dependency, or support issue.
  5. Patch, test, and update release gates.
  6. Notify affected users when legally required or materially useful.
  7. Update the command center, release notes, and support macros.

Source References