We release patches for security vulnerabilities. Currently supported versions:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of Document Intelligence AI seriously. If you believe you have found a security vulnerability, please report it to us as described below.
- Open a public GitHub issue
- Discuss the vulnerability publicly before it has been addressed
- Email security@document-intelligence.ai with details
- Include steps to reproduce the vulnerability
- Allow us reasonable time to address the issue before public disclosure
- Acknowledgment: Within 48 hours of your report
- Initial Assessment: Within 5 business days
- Regular Updates: Every 5 business days until resolution
- Credit: Security researchers who report valid vulnerabilities will be acknowledged (unless anonymity is requested)
- API key-based authentication with RBAC
- JWT tokens with short expiration times
- Principle of least privilege access controls
- Encryption at rest using AES-256
- TLS 1.3 for all data in transit
- Secure key management using HashiCorp Vault
- PII detection and automatic redaction
- Container scanning in CI/CD pipeline
- Regular dependency updates via Dependabot
- Network isolation and firewall rules
- Intrusion detection and prevention systems
- SOC 2 Type II certified
- GDPR compliant data handling
- HIPAA ready architecture
- Regular third-party security audits
-
API Keys
- Rotate API keys regularly (recommended: every 90 days)
- Never commit API keys to version control
- Use environment variables for key storage
- Implement key scoping for minimal permissions
-
Network Security
- Always use HTTPS endpoints
- Implement IP allowlisting where possible
- Use VPN or private connections for sensitive data
-
Data Handling
- Minimize data retention periods
- Implement data classification policies
- Regular audit of access logs
- Use field-level encryption for sensitive data
- 0-30 days: Issue verification and fix development
- 30-60 days: Testing and staged rollout
- 60-90 days: Full deployment and monitoring
- 90+ days: Public disclosure (if applicable)
Security Team: security@document-intelligence.ai PGP Key: Download Public Key