DIN 0815/R2 · SECURITY
Security.
Responsible disclosure process and what to do if you find something.
How to report.
Email security@0815software.com with a description of the issue, steps to reproduce, and the affected repository or module. We will acknowledge receipt within two business days and aim to resolve critical issues within 14 days.
Do not open a public GitHub issue for security vulnerabilities. Use the email address above. We will coordinate disclosure timing with you.
SECURITY CONTACT
security@0815software.com What is in scope.
SQL injection / XSS / CSRF In scope — report via email
Authentication bypass In scope — report via email
Privilege escalation In scope — report via email
Data exposure in API responses In scope — report via email
Dependency vulnerabilities (critical) In scope — reference CVE if available
Denial of service (resource exhaustion) Out of scope for disclosure; file a GitHub issue
Social engineering / phishing Out of scope
Physical security Out of scope
We do not have a formal bug bounty programme. If you report a valid, in-scope vulnerability, we will credit you in the changelog and the repository security advisories — unless you prefer to remain anonymous.