Skip to content

Security: OpenLegalCore/community

Security

SECURITY.md

Security and Sensitive Information

Do not report vulnerabilities, active incidents, credentials, private URLs, deployment details, private legal documents, personal data or other sensitive information in public issues or Discussions.

The canonical project-wide policy is published at openlegalcore.org/security.

Reporting route

  1. If the matter affects a specific public repository, use that repository's Security tab and GitHub Private Vulnerability Reporting when available.
  2. Otherwise, or when the affected boundary is unclear, email security@openlegalcore.org with the subject OpenLegalCore security report.
  3. Begin with a concise description. Share only the minimum information needed to establish a safe private reporting route, and do not attach confidential material until the recipient and handling method are confirmed.

If neither route is temporarily available, do not open a public report.

What to include privately

  • the affected component and version or commit;
  • observed behavior, likely impact and required preconditions;
  • reproducible steps using synthetic data where possible;
  • relevant evidence with secrets and personal data removed;
  • any known mitigation; and
  • a safe contact path for clarification.

What not to send

Do not send credentials, tokens, private keys, personal or legal documents, production datasets, third-party confidential data or unredacted operational logs. Describe the category of sensitive material first and wait for a suitable exchange method.

Handling and boundary

A report is reviewed privately, clarification is requested when needed and disclosure is coordinated after a safe fix or mitigation is available. The project does not promise a response time and does not operate a bug-bounty program.

This reporting guidance does not authorize testing. Do not disrupt services, use social engineering, access third-party data, establish persistence or exfiltrate information.

There aren't any published security advisories