Current design principles
- AI provider credentials belong on the server and must never use a
NEXT_PUBLIC_environment variable. - Workspace access should be enforced server-side through the Ace ID authentication flow, not by hiding UI elements.
- Tool execution should remain allowlisted and bounded; model output is untrusted input.
- Public embed snippets and agent instructions must not contain secrets.
- Transport security headers are configured at the application layer. This is not a substitute for dependency review, access control, monitoring, or deployment testing.
Report a vulnerability
Please do not publish exploit details, credentials, personal data, or live attack instructions in public. Request a private disclosure channel through the Acetheticsx GitHub profile and include a concise impact description, affected URL or component, and reproducible steps that do not expose other users’ data.
A dedicated, monitored security contact should be established by the operator before broad public launch. Do not assume that a report has been received until the operator confirms it.
Scope and limitations
Only test systems you own or have explicit permission to assess. Avoid denial-of-service testing, social engineering, data exfiltration, or access to another user’s account. Security controls can change and may have gaps; the current public deployment must be independently tested.
Secrets and incidents
If a credential is exposed, revoke or rotate it immediately and review access logs where available. Do not paste live credentials into support requests or issue descriptions.