Skip to content

Security: openclaw/proc-safe

Security

SECURITY.md

Security policy

Report vulnerabilities privately using GitHub Security Advisories or security@openclaw.ai. Include the affected version, runtime and OS, a minimal reproduction, and demonstrated impact. Do not include credentials or unrelated private process information.

PID reuse, inaccurate identity, false absence, incomplete observations, native memory safety, resource lifetime, and package publication integrity are security boundaries. Applications remain responsible for authorization, service membership policy, retries, and operating-system isolation. A successful observation is a snapshot, not a lock on future PID ownership.

There is no paid bug bounty program.

There aren't any published security advisories