# Security Policy ## Our commitment DevSwarm takes security seriously. We are committed to protecting user data, code, and privacy. ## Data collection and privacy **DevSwarm is designed with privacy-first principles:** - Your code stays on your machine - AI assistants run through your own credentials, or locally - Sensitive data stored on-device is encrypted at rest using the operating system's built-in encryption ## Reporting security vulnerabilities If you discover a security vulnerability, please report it responsibly: **For sensitive security issues:** - Email: security@devswarm.ai - Include detailed steps to reproduce - Allow reasonable time for response and fix **For general security concerns:** - Open an issue using our [bug report template](https://github.com/devswarm-ai/devswarm/issues/new?template=bug.yml) - Tag with "security" label ## Security best practices When using DevSwarm: - Keep your AI assistant credentials and API keys secure - Review generated code before committing - Use appropriate branch permissions for sensitive repositories - Follow your organization's security policies - Follow the security recommendations of any/all coding assistant(s) you are using ## Updates We will notify users of security updates through: - GitHub releases - Email notifications (if subscribed) - In-app notifications for critical updates Last updated: 2026-07-20