Security Policy
Security Policy
Section titled “Security Policy”Canonical policy: repository root
SECURITY.md.
For how to report issues, see Vulnerability reporting.
Overview
Section titled “Overview”Kazma is a single-operator trusted-host agent by default. Localhost + a
strong KAZMA_SECRET + HITL is the recommended daily posture. Public multi-user
SaaS is not the default threat model.
Supported versions
Section titled “Supported versions”| Version | Support |
|---|---|
| 0.6.x | Full support |
| 0.5.x | Critical security fixes only |
| < 0.5 | Unsupported |
Security features (summary)
Section titled “Security features (summary)”HITL & permissions
Section titled “HITL & permissions”Danger tools go through HITL gates (graph interrupt, swarm bus, pipeline checkpoints). Skills declare permissions; MCP tools are classified by risk. See Security & Safety.
Secrets
Section titled “Secrets”API keys and vault material must never be committed. Prefer KAZMA_VAULT_KEY
and ConfigStore vault refs. Never use the historical default
kazma-local-dev-secret.
Audit trail
Section titled “Audit trail”Privileged actions (skill installs, permission changes, security-relevant events) are logged when the audit path is enabled. Treat completeness as deployment-dependent — verify in your environment.
Skill certification
Section titled “Skill certification”Skills that pass validation checks may receive a Kazma-Certified badge (manifest, entry point, permissions, MCP types, pattern scan). Certification is not a formal third-party audit.
No paid bug bounty
Section titled “No paid bug bounty”There is no cash bounty program at this time. Responsible disclosure only —
see Vulnerability reporting and SECURITY.md.