Security Policy
How to report vulnerabilities and how EmbeddedOS is built to be secure.
Do not open a public GitHub issue for security vulnerabilities. Email security@embeddedos.org with details. We will respond within 48 hours.
Responsible Disclosure
Email security@embeddedos.org with vulnerability details. We follow a 90-day disclosure timeline. Critical vulnerabilities are patched within 7 days.
Scope
All EmbeddedOS repositories on GitHub are in scope: EoS kernel, eBootloader, EAI, ENI, EIPC, eBuild, EoSim, EoStudio, eDB, eBrowser, eOffice, and all related tooling.
Out of Scope
Third-party dependencies, GitHub infrastructure, social engineering attacks, and physical attacks on hardware are out of scope.
Recognition
Security researchers who responsibly disclose valid vulnerabilities are credited in the security advisory and our Hall of Fame.
