Skip to main content

Security Policy

We appreciate responsible disclosure of security vulnerabilities. Please follow the guidance below so we can investigate and resolve issues quickly.

Reporting a Vulnerability

Use our dedicated security contact and do not file a public issue:

When reporting, please include:

  • A clear description of the issue and potential impact
  • Steps to reproduce (proof of concept if available)
  • Affected pages, files, or URLs
  • Any relevant logs, screenshots, or configuration details

Disclosure Expectations

  • Please keep the report private until we confirm a fix or provide guidance.
  • We will coordinate a disclosure timeline with you if the issue is confirmed.
  • We may request additional details to validate or reproduce the report.

Response Timelines

We aim to:

  • Acknowledge receipt within 3 business days
  • Triage and provide an initial assessment within 7 business days
  • Remediate confirmed issues within 30 business days, or provide a status update and revised timeline

Scope

This policy covers:

  • Documentation content in this repository
  • Published documentation at https://docs.nanores.org (or its current public domain)

Out of scope (unless it directly affects this repository) includes:

  • Third-party services and infrastructure not controlled by this project
  • Social engineering or physical security issues

Thank you for helping keep the project and community safe.