If you discover a security vulnerability in Pharos, please report it responsibly. Do not open a public GitHub issue.
Email: julius.olsson05@gmail.com
Include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You should receive an acknowledgement within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.
The following are in scope:
- The Pharos web application at conflicts.app
- The open-source codebase at github.com/Juliusolsson05/pharos-ai
- API endpoints under
/api/v1/
The following are out of scope:
- Third-party services (Supabase, Vercel, PostHog)
- Social engineering attacks
- Denial of service attacks
Only the latest version deployed to main is supported with security updates.