Skip to content

Security: CredenceOrg/Credence-Backend

Security

SECURITY.md

Security Policy

We take the security of this project seriously. If you believe you have found a security vulnerability, please report it to us confidentially.

Reporting a Vulnerability

Please do not report security vulnerabilities via public GitHub issues.

Please report vulnerabilities through GitHub's Private Vulnerability Reporting feature for this repository:

  1. Navigate to the repository page on GitHub.
  2. Click on the "Security" tab.
  3. Click "Advisories" and then "Report a vulnerability".

If Private Vulnerability Reporting is not active or you need to contact the maintainers directly, please check the repository's main profile/organization page for contact details.

Response Process

Reported vulnerabilities will be triaged and addressed in accordance with the severity gates and SLAs defined in the Security Architecture.

Safe Harbor

We will not take legal action against you or request law enforcement to investigate you if you act in good faith, report the vulnerability to us promptly, and adhere to the guidelines of this policy.

There aren't any published security advisories