{"schema":"bay-run.security-policy.v1","service":"bay-run","build":{"source_sha":"067d3be66e76897ce7a21b1598e37c96b454262c","image_digest":"sha256:0d419d6de42b7a247336d3d07e8cffcf2895840fb7811cfd5584096efafb8d9f","binding_status":"complete","generated_at":"2026-10-02T18:07:10Z"},"self_assessment":{"assessment_type":"implementation-backed self-assessment","independent_security_audit_completed":false,"penetration_test_claimed":false,"certifications_claimed":[]},"reporting":{"public_intake":true,"monitored_mailbox":null,"contact_status":"published_not_release_verified","monitoring_evidence":"not_independently_verified_by_release","contact":"mailto:security@huggingbay.xyz","organization_security_page":"https://run.huggingbay.xyz/security","instructions_url":"https://run.huggingbay.xyz/security","limitation":"The organization publishes a dedicated security mailbox, but this release did not independently verify mailbox delivery, alerting, or monitoring. Bay Run does not claim a response-time SLA, independent triage certification, or encrypted-mail key. Do not use task, memory, catalog-request, or payment routes to submit reports.","next_actions":["Email a minimal report to security@huggingbay.xyz; do not include credentials, secrets, or unrelated private task data.","Record the release_id, generated_at, endpoint, and status from the relevant public document.","Coordinate a secure transfer method with the security contact before sending sensitive proof material or exploit payloads."]},"related_surfaces":{"security_txt":"https://run.huggingbay.xyz/.well-known/security.txt","assurance":"https://run.huggingbay.xyz/.well-known/assurance.json","data_policy":"https://run.huggingbay.xyz/.well-known/data-policy.json"}}