HaleES treats security and privacy as part of the architecture.
This public repository is an architecture specification. It does not contain the production Sensei OS runtime, private infrastructure, private datasets, secrets, or commercial product code.
If you find a security concern related to this public specification, do not post sensitive details in a public issue.
Report the concern privately through the contact channel listed by the project owner or through the official HaleES contact path when available.
A useful report should include the affected document, the concern, why it matters, and any safe reproduction notes that do not expose secrets or private system details.
Public issues are appropriate for documentation clarity, spelling corrections, public examples, rubric discussion, contract format questions, and general architecture feedback.
Public issues are not appropriate for secrets, credentials, private customer data, private deployment details, exploit steps, unreleased runtime behavior, internal model routing, private memory boundaries, or production infrastructure details.
This security policy applies to the public architecture specification in this repository.
The commercial HaleES product, production Sensei OS runtime, hosted infrastructure, private connectors, private memory implementation, and private datasets remain outside this public specification repository.
The public architecture should help people understand the governance pattern without exposing the private runtime.
Security issues should be handled with care, privacy, and enough detail to fix the problem without putting the system or users at risk.