Skip to content

Security: devswarm-ai/devswarm

Security

SECURITY.md

Security Policy

Our commitment

DevSwarm takes security seriously. We are committed to protecting user data, code, and privacy.

Data collection and privacy

DevSwarm is designed with privacy-first principles:

  • Your code stays on your machine
  • LLM interactions use your own API keys, or runs locally
  • Telemetry can be turned off anytime in settings

Reporting security vulnerabilities

If you discover a security vulnerability, please report it responsibly:

For sensitive security issues:

  • Email: security@devswarm.ai
  • Include detailed steps to reproduce
  • Allow reasonable time for response and fix

For general security concerns:

Security best practices

When using DevSwarm:

  • Keep your LLM API keys secure
  • Review generated code before committing
  • Use appropriate branch permissions for sensitive repositories
  • Follow your organization's security policies
  • Follow the seucrity recommendations of any/all coding assistant(s) you are using

Updates

We will notify users of security updates through:

  • GitHub releases
  • Email notifications (if subscribed)
  • In-app notifications for critical updates

Last updated: 2025-09-08

There aren’t any published security advisories