Skip to content

Security: neurosamAI/tow-cli

Security

SECURITY.md

Security Policy

Tow is created by Murry Jeong (comchangs) and supported by neurosam.AI. We take security seriously.

Supported Versions

Version Supported
0.3.x
0.2.x
0.1.x

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to:

oss@neurosam.ai

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 1 week
  • Fix & Disclosure: Coordinated with reporter

Security Best Practices

When using Tow, please follow the security guidelines in our documentation:

  • Never commit SSH keys or passwords to tow.yaml
  • Use environment variables (${VAR}) for sensitive values
  • Add tow.local.yaml to .gitignore
  • Enable branch policies for production environments
  • Maintain ~/.ssh/known_hosts for host key verification

neurosam.AI

There aren’t any published security advisories