Skip to content
kazma.
ع Star 6 Get Started

Security Policy

Canonical policy: repository root SECURITY.md. For how to report issues, see Vulnerability reporting.

Kazma is a single-operator trusted-host agent by default. Localhost + a strong KAZMA_SECRET + HITL is the recommended daily posture. Public multi-user SaaS is not the default threat model.

VersionSupport
0.6.xFull support
0.5.xCritical security fixes only
< 0.5Unsupported

Danger tools go through HITL gates (graph interrupt, swarm bus, pipeline checkpoints). Skills declare permissions; MCP tools are classified by risk. See Security & Safety.

API keys and vault material must never be committed. Prefer KAZMA_VAULT_KEY and ConfigStore vault refs. Never use the historical default kazma-local-dev-secret.

Privileged actions (skill installs, permission changes, security-relevant events) are logged when the audit path is enabled. Treat completeness as deployment-dependent — verify in your environment.

Skills that pass validation checks may receive a Kazma-Certified badge (manifest, entry point, permissions, MCP types, pattern scan). Certification is not a formal third-party audit.

There is no cash bounty program at this time. Responsible disclosure only — see Vulnerability reporting and SECURITY.md.