If you discover a security vulnerability, please report it responsibly:
Email: founders@runanywhere.ai
Please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Resolution: Depends on severity (critical issues prioritized)
This policy covers:
- RunAnywhere SDKs (Swift, Kotlin, React Native, Flutter, Web, Electron, Python)
- CLI (
rcli) and shared C/C++ core (runanywhere-commons) - Native inference engines and runtime modules
- Example applications in this repository
Please do not publicly disclose vulnerabilities until we've had a chance to address them. We appreciate your help in keeping our users safe.