Skip to content

Explicitly communicating security boundaries and policy - #691

Open
planetchili wants to merge 1 commit into
mainfrom
docs/security-communication
Open

planetchili wants to merge 1 commit into
mainfrom
docs/security-communication

Conversation

@planetchili

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The policy needs clarification around child-pipe access and privileged ETW data.

Review effort: Lite
Findings: None

What changed in this PR

Documents PresentMon’s security boundaries, threat model, vulnerability scope, and reporting requirements.

Changes:

  • Defines telemetry confidentiality and local-client assumptions.
  • Clarifies security scope and exclusions.
  • Expands vulnerability-reporting guidance.
File Description
SECURITY.md Adds the security model, scope, exclusions, and reporting details.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants