# Security Policy ## Reporting Vulnerabilities The Bastionguard project takes security issues seriously and is committed to responsible vulnerability handling. We encourage responsible disclosure of any security weakness that may impact the confidentiality, integrity, or availability of the system. This includes, but is not limited to: - Cryptographic weaknesses or key compromise - Authentication or authorization bypass - Remote code execution - Privilege escalation - Data leakage - Denial of Service vulnerabilities - Insecure default configurations --- ## Reporting Process Security issues must be reported privately and must not be disclosed publicly before a fix or mitigation is available. Please contact the security team using one of the following channels: - **Email:** info@bastionguard.eu - **PGP Fingerprint:** E33B 4BC4 CAC6 FA6F 1CCA 2397 68D0 8974 A276 CF8A Encrypted communication is strongly preferred. --- ## Report Requirements To ensure efficient analysis, reports should include: - A detailed description of the vulnerability - Affected versions and components - Steps to reproduce the issue - Proof of concept, when available - Potential impact assessment Incomplete or unverifiable reports may not be prioritized. --- ## Responsible Disclosure Reporters are expected to: - Allow reasonable time for investigation and remediation - Avoid exploiting the vulnerability beyond proof of concept - Refrain from public disclosure until coordinated with maintainers The project commits to: - Acknowledge valid reports in a timely manner - Provide status updates when appropriate - Credit reporters, upon request --- ## Legal Safe Harbor The Bastionguard project considers security research conducted in good faith and in accordance with this policy to be authorized. We will not pursue legal action against researchers who: - Act in good faith - Avoid privacy violations and service disruption - Respect this disclosure process - Do not exploit vulnerabilities for personal gain --- ## Scope This policy applies to: - Core platform components - Official plugins and extensions - Deployment scripts and configuration templates - Official documentation and tooling Third-party integrations are excluded unless explicitly stated. --- ## Policy Updates This Security Policy may be updated to reflect technical, legal, or operational changes. All updates will be published in this repository.