DIN 0815 · STANDARD SOFTWARE REV 2026.04 ● LIVE

How to report.

Email security@0815software.com with a description of the issue, steps to reproduce, and the affected repository or module. We will acknowledge receipt within two business days and aim to resolve critical issues within 14 days.

Do not open a public GitHub issue for security vulnerabilities. Use the email address above. We will coordinate disclosure timing with you.

SECURITY CONTACT

What is in scope.

SQL injection / XSS / CSRF In scope — report via email
Authentication bypass In scope — report via email
Privilege escalation In scope — report via email
Data exposure in API responses In scope — report via email
Dependency vulnerabilities (critical) In scope — reference CVE if available
Denial of service (resource exhaustion) Out of scope for disclosure; file a GitHub issue
Social engineering / phishing Out of scope
Physical security Out of scope

We do not have a formal bug bounty programme. If you report a valid, in-scope vulnerability, we will credit you in the changelog and the repository security advisories — unless you prefer to remain anonymous.