BastionGuard/SECURITY.md
2026-02-06 21:15:53 +01:00

2.4 KiB

Security Policy

Reporting Vulnerabilities

The Bastionguard project takes security issues seriously and is committed to responsible vulnerability handling.

We encourage responsible disclosure of any security weakness that may impact the confidentiality, integrity, or availability of the system.

This includes, but is not limited to:

  • Cryptographic weaknesses or key compromise
  • Authentication or authorization bypass
  • Remote code execution
  • Privilege escalation
  • Data leakage
  • Denial of Service vulnerabilities
  • Insecure default configurations

Reporting Process

Security issues must be reported privately and must not be disclosed publicly before a fix or mitigation is available.

Please contact the security team using one of the following channels:

Encrypted communication is strongly preferred.


Report Requirements

To ensure efficient analysis, reports should include:

  • A detailed description of the vulnerability
  • Affected versions and components
  • Steps to reproduce the issue
  • Proof of concept, when available
  • Potential impact assessment

Incomplete or unverifiable reports may not be prioritized.


Responsible Disclosure

Reporters are expected to:

  • Allow reasonable time for investigation and remediation
  • Avoid exploiting the vulnerability beyond proof of concept
  • Refrain from public disclosure until coordinated with maintainers

The project commits to:

  • Acknowledge valid reports in a timely manner
  • Provide status updates when appropriate
  • Credit reporters, upon request

The Bastionguard project considers security research conducted in good faith and in accordance with this policy to be authorized.

We will not pursue legal action against researchers who:

  • Act in good faith
  • Avoid privacy violations and service disruption
  • Respect this disclosure process
  • Do not exploit vulnerabilities for personal gain

Scope

This policy applies to:

  • Core platform components
  • Official plugins and extensions
  • Deployment scripts and configuration templates
  • Official documentation and tooling

Third-party integrations are excluded unless explicitly stated.


Policy Updates

This Security Policy may be updated to reflect technical, legal, or operational changes.

All updates will be published in this repository.