diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..f7a212a1 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,26 @@ +# Security policy + +## Reporting a Vulnerability + +**Please do not report security vulnerabilities through public GitHub issues.** + +Please report any vulnerability or any bug that could potentially affect the security of users' funds by mail to: + +- [`kdmukai.vision749@passmail.net`](mailto:kdmukai.vision749@passmail.net) +- [`nick@klockenga.net`](mailto:nick@klockenga.net) + +In the subject type `[SeedSigner] Security Report: ` +and in the body a long description describing the issue. We aim to respond +within one week and patch within 90 days. + +### What to include + +To help triage the report quickly, please include as much of the following as you can: + +- The SeedSigner version +- A description of the vulnerability and its impact +- Steps to reproduce, ideally with a proof of concept + +## Scope + +This policy covers SeedSigner and related build repos (ie seedsigner-os). \ No newline at end of file