Skip to content

Security: Novaya-AI/novgraph

Security

SECURITY.md

Security

novgraph stores an API key and edits coding agents' configuration files, so we take reports seriously.

Please don't open a public issue for a vulnerability. Email shourya@trynovaya.com with what you found and how to reproduce it. We'll reply within three working days.

In scope: this client — key storage, config edits, the MCP bridge, anything that could leak a key or damage a config. The hosted Novayagraph service is in scope too; report it the same way.

There aren't any published security advisories