Skip to content

Security: thefayth/papercut

Security

SECURITY.md

Security Policy

Papercut is built around a protected public surface and private operational engine.

Public Repository Scope

This repository should contain public-safe documentation, diagrams, brand notes, and selected approved visuals only. It should not contain:

  • source code
  • credentials
  • provider tokens
  • environment files
  • private prompts or agent instructions
  • uploaded documents
  • signatures
  • faxes
  • packet artifacts
  • screenshots from private work
  • customer, student, benefits, medical, legal/admin, or family records

Reporting

If you believe a public material reveals private information or creates a security issue, contact Faith Cheltenham through FaithCheltenham.com with:

  • the file path or URL
  • the concern
  • the smallest useful reproduction detail

Do not include private credentials, exploit payloads, or sensitive third-party data in a public issue.

Dispatch Safety

Papercut live dispatch is expected to remain gated by:

  • review-only mode
  • provider credentials
  • authenticated private routes
  • per-item approval
  • destination trust
  • audit receipts

No public demo should send real email, fax, portal, ATS, or worker actions.

There aren't any published security advisories