INFOSECOSINT · CTI · GEOIP · MODELS · DECISION GRAPH
Security policy

Security

Dual-forge supply chain: GitHub for code, Hugging Face for models / datasets / spaces. Legal public-source only.

Reporting

Email security@secur.ist (ops: ops@secur.ist) with affected surface, impact, and legal reproduction steps. Do not open public issues for unfixed security problems.

Dual-forge supply chain

  • GitHub lane: public org packages only; Scout is rate-limited; legal_risk tags; no private repo access.
  • Hugging Face lane: public hub APIs via User-Agent securist-scout; model card license review required before fielding; operator-controlled cache only — never illegal rehost.
  • TARX: upstream local private runtime. Integrate; do not vendor. Model fielding = offline pull + docs; no dark phone-home on weights.
  • Geo: MaxMind GeoLite2 honesty — city/ASN class signals only. No household GeoIP claims.
  • Telemetry: implementer package telemetry only. Weights stay offline on operator metal.

License review

Every HF catalog row and Scout prompt requires license / card review before pull. Prefer explicit OSS licenses. When uncertain, legalRisk = review and stop.

Edge + origin controls (live)

  • Transport: HSTS preload-class max-age, HTTPS only, TLS ≥ 1.2 at edge when Cloudflare is in path.
  • Browser isolation: CSP (default-src self; no frames), X-Frame-Options DENY, COOP/CORP same-origin, nosniff, locked Permissions-Policy.
  • Vercel WAF: deny common exploit probes (wp-admin, .env, .git, phpunit, aws creds); rate-limit aggressive clients; deny empty UA on write methods.
  • Disclosure: /.well-known/security.txt
  • Cloudflare: nameservers live; Full (strict) SSL, Always HTTPS, Rocket Loader off, security level high — see DEPLOY.md / scripts/cloudflare-secure-securist.sh.

Out of scope

  • Unauthorized access, credential stuffing, malware distribution
  • Private multiplayer spy networks
  • Consulting marketplace or sales funnels
  • Personal contributor marketing on public surfaces

Ethics / AUP: /legal