-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Responsible Disclosure page #58
Comments
Draft — Responsible Disclosure PolicyIntroductionAt Secure Internet Voting (SIV), we prioritize the security of our systems and data. We recognize the valuable role that ethical security researchers and our community play in maintaining the security and integrity of our services. This Responsible Disclosure Policy is designed to give clear guidelines on how to responsibly report identified security vulnerabilities. ScopeThis policy applies to any security vulnerabilities you believe you have discovered in any product, service, or system offered by SIV. We request that you do not disclose the vulnerability to the public or third parties in a manner that can cause harm or damage. Reporting a VulnerabilityIf you believe you have found a security vulnerability, please report it to us as soon as possible. We ask that you:
Our CommitmentUpon receiving your report, we commit to:
ConfidentialityWe ask that you keep your findings confidential until we have had a chance to address them. We understand that not all security issues can be immediately fixed and require time to patch. We aim to resolve all issues as quickly as possible, and we ask for your cooperation in maintaining confidentiality during this period. RecognitionWe believe in recognizing the efforts of security researchers who responsibly disclose vulnerabilities. We will acknowledge your contribution in our security update communications, should you wish. LimitationsWhile we encourage the reporting of security vulnerabilities, please note:
Contact UsFor any questions or concerns, please contact [[email protected]]. |
Or something a bit less formal — Responsible Disclosure at Secure Internet Voting (SIV)Spot a Security Issue? Let’s Tackle It TogetherIntroWe’re all about security at SIV, but nobody's perfect. If you’ve noticed a security problem in our systems, we want to be the first to know. We ask that you don’t share this publicly until we’ve had a chance to fix it. Got a Security Tip?Send us a note at [email protected]. Include these details:
Our Promise to You:
Confidentiality MattersWe ask for your discretion until the issue is resolved. Some fixes take time, and we’re committed to getting it right. Credits Where They're DueWe appreciate your help and are happy to give credit in security updates, if you like. Heads-Up
Questions or Thoughts?Feel free to reach out at [email protected]. |
We discussed yesterday wanting to add a page outlining our philosophy about responsible disclosures.
Contents:
The text was updated successfully, but these errors were encountered: