Skip to content

Security: IRISX-AI/IRIS-X

Security

SECURITY.md

πŸ”’ Security Policy β€” IRIS-MX

At IRISX-AI, security and privacy are fundamental principles of our design architecture.


πŸ”‘ Bring Your Own Key (BYOK) Architecture

  • Local Encryption: All user API credentials (including Gemini API Keys) are encrypted locally using native mobile hardware keystore APIs.
  • Zero Third-Party Relays: Your credentials and voice streams are routed directly from your mobile device to Gemini Live API endpoints. No intermediary servers store or inspect user voice data.

πŸ›‘οΈ Reporting a Vulnerability

If you discover a security vulnerability within IRIS-MX or the public UI shell, please report it responsibly:

  1. Do NOT open a public issue on GitHub.
  2. Email the vulnerability details directly to irisaidevop@gmail.com.
  3. Include clear steps to reproduce the issue, proof of concept, and affected versions.

We appreciate your effort in responsibly disclosing findings to keep our users safe.


πŸ“œ Commercial & Security Inquiries

For enterprise licensing, security audits, or private source code requests, please reach out to irisaidevop@gmail.com or visit https://www.irisxai.in.

There aren't any published security advisories