{"schema":"bay-run.security-policy.v1","service":"bay-run","build":{"release_id":"bay-run-mvp-mvp32-acd874527730dc7f94c07eecd696a9f26f281d12","release_id_source":"cloud_run_revision","source_sha":"acd874527730dc7f94c07eecd696a9f26f281d12","image_digest":"us-central1-docker.pkg.dev/barneyserver/hugging-bay-workers/bay-run@sha256:fb33127a500c5feb547645731b4bf45df293a36a32fb2f8b718564ab88a4288c","binding_status":"complete","generated_at":"2026-08-15T03:31:20Z"},"self_assessment":{"assessment_type":"implementation-backed self-assessment","independent_security_audit_completed":false,"penetration_test_claimed":false,"certifications_claimed":[]},"reporting":{"public_intake":true,"monitored_mailbox":null,"contact_status":"published_not_release_verified","monitoring_evidence":"not_independently_verified_by_release","contact":"mailto:security@huggingbay.xyz","organization_security_page":"https://run.huggingbay.xyz/security","instructions_url":"https://run.huggingbay.xyz/security","limitation":"The organization publishes a dedicated security mailbox, but this release did not independently verify mailbox delivery, alerting, or monitoring. Bay Run does not claim a response-time SLA, independent triage certification, or encrypted-mail key. Do not use task, memory, catalog-request, or payment routes to submit reports.","next_actions":["Email a minimal report to security@huggingbay.xyz; do not include credentials, secrets, or unrelated private task data.","Record the release_id, generated_at, endpoint, and status from the relevant public document.","Coordinate a secure transfer method with the security contact before sending sensitive proof material or exploit payloads."]},"related_surfaces":{"security_txt":"https://run.huggingbay.xyz/.well-known/security.txt","assurance":"https://run.huggingbay.xyz/.well-known/assurance.json","data_policy":"https://run.huggingbay.xyz/.well-known/data-policy.json"}}