ROSS is under active development and is not approved for confidential, privileged, regulated, proprietary, or real client material in an operator-hosted environment.
Use GitHub private vulnerability reporting for this repository. Do not include client information, production credentials, unnecessary personal information, or exploit details in a public issue. A public issue may be used for a non-sensitive software defect only.
The project does not yet publish a response-time commitment because the legal
operator and security owner are unassigned. The incident process in
docs/security/incident-response.md is the engineering response model, not an
operational service-level agreement.
No production release is supported. The default branch is the only engineering line receiving security changes. Fork operators are responsible for their own deployment, access control, secrets, dependencies, logs, backups, retention, vendors, monitoring, and incident response.