Release Council

Security model

Last updated 12 July 2026

Least privilege

URL-only inspections require no repository access. GitHub is optional and read-only by default. Code writes require separate authorisation for a branch or draft pull request.

Browser isolation

Each inspection uses a fresh server-controlled browser context. Target credentials are supplied directly to that context and excluded from transcripts, findings and AI prompts.

Evidence boundaries

Browser observations, source readiness and authenticated provider proof are recorded separately. A route response or repository implementation is not treated as proof of a completed external deployment.

Human approval

External writes, destructive actions, purchases, permission changes and deployments require explicit approval. Generated remediation is tested and returned for review.

Reporting

Report suspected vulnerabilities privately to security@releasecouncil.app. For production incidents or service-impacting support, contact support@releasecouncil.app. Do not include sensitive exploit details in public issues. Receipt is a contact path, not a claim that an incident has been resolved.