Skip to content

Explicitly communicating security boundaries and policy - #691

Merged
markgalvan-intel merged 1 commit into
mainfrom
docs/security-communication
Sep 28, 2026
Merged

markgalvan-intel merged 1 commit into
mainfrom
docs/security-communication

Conversation

@planetchili

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The policy needs clarification around child-pipe access and privileged ETW data.

Review effort: Lite
Findings: None

What changed in this PR

Documents PresentMon’s security boundaries, threat model, vulnerability scope, and reporting requirements.

Changes:

  • Defines telemetry confidentiality and local-client assumptions.
  • Clarifies security scope and exclusions.
  • Expands vulnerability-reporting guidance.
File Description
SECURITY.md Adds the security model, scope, exclusions, and reporting details.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@markgalvan-intel
markgalvan-intel merged commit 00db2ca into main Sep 28, 2026
1 check passed
@markgalvan-intel
markgalvan-intel deleted the docs/security-communication branch September 28, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants