Skip to content

Security: yashowardhansinghtomar/rag-evaluation-workbench

Security

SECURITY.md

Security

This repository is a local RAG evaluation demo. It does not require API keys, private documents, or live model calls.

Data Handling

Do not commit:

  • Private documents.
  • Customer or tenant records.
  • API keys, tokens, or credentials.
  • Proprietary policies or contracts.

Use synthetic, public, or redacted examples in the corpus and eval cases.

RAG-Specific Risk

RAG systems can expose sensitive source text if private documents are indexed without access controls. This demo does not implement authentication, authorization, or document-level permissions.

If adapting this for production, add:

  • Document access checks before retrieval.
  • Logging rules that avoid sensitive text leakage.
  • Redaction for reports.
  • Source-level permissions.

Reporting Issues

If you find a security issue, open a private report through GitHub Security Advisories if available. If that is not available, contact the repository owner directly and avoid posting sensitive details in a public issue.

There aren't any published security advisories