Files
anonymizer/SECURITY.md
Mobiletic 81b6b03239 feat: harden generic preset, add LLM retry, and finish tooling/docs
- PatternDef.validate + Luhn-gated credit-card detection; de-overlap the
  generic phone/date/IP patterns; presets.swiss unchanged (production behavior)
- strip g/y flags from nameHint so .test() is stateless (latent footgun)
- openAICompatibleProvider: bounded retry on transient failures (network /
  timeout / 429 / 5xx), configurable via retries + retryDelayMs
- eslint + prettier + vitest coverage (97%); CI runs lint/format/coverage
- docs: README badges + new-option docs, SECURITY.md, issue/PR templates

26 tests passing; build emits ESM+CJS+types.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 17:03:20 +01:00

29 lines
1.2 KiB
Markdown

# Security Policy
## Reporting a vulnerability
This library handles personal data, so we take security and privacy issues seriously — especially any
path that could cause PII to **leak** (e.g. a placeholder that isn't restored, or sensitive text reaching
a downstream service un-anonymized).
**Please do not open a public issue for security problems.** Instead, email **security@mobiletic.com**
with:
- a description of the issue and its impact,
- steps to reproduce (a minimal code sample or failing test is ideal),
- the package version and Node.js version.
We aim to acknowledge reports within a few business days and will keep you updated on remediation. Once a
fix is released, we're happy to credit you (unless you prefer to remain anonymous).
## Supported versions
This project is pre-1.0; security fixes land on the latest published release. We recommend always running
the most recent version.
## Scope & disclaimer
This library is a **best-effort** pseudonymization aid, not a guarantee of regulatory compliance. LLM and
regex detection can miss or misclassify data. Validate against your own requirements (nLPD, GDPR, HIPAA, …)
before relying on it for regulated data.