Skip to content

Security: Coyls/septm-backend

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report them privately by email: security@septm.xyz

Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact

I will acknowledge your report within 72 hours and aim to release a fix within 14 days depending on severity.

Scope

In scope:

  • Authentication and session handling
  • API endpoints and authorization
  • Data exposure or injection vulnerabilities

Out of scope:

  • Denial of service attacks
  • Issues requiring physical access to the server
  • Vulnerabilities in third-party dependencies (report those upstream)

Disclosure policy

I follow coordinated disclosure. Please allow time for a fix to be released before making a vulnerability public.

There aren't any published security advisories