Skip to content
English

Security reporting

Custodexa’s job is to keep evidence for other systems, so a security issue in the product itself is handled at the highest priority. This page explains where to send a finding, what to include, and the disclosure rhythm that follows.

  1. A private vulnerability report on GitHub (preferred): open a private report under the main repository’s security advisories, whose content stays private.
  2. Email: write to security@custodexa.org.

Please include the steps to reproduce, an assessment of the impact, and the version you tested. Reports from both channels go through the same process.

  • Send details of an unpatched vulnerability through the private channels above rather than opening a public issue.
  • You will get a reply on the progress, and once the fix is released the timing of public disclosure is coordinated with you.
  • SECURITY.md in the main repository is the authoritative version of the full policy, in English, with a Traditional Chinese version shipped alongside it.

This page describes the project’s reporting process and produces no audit events inside the product. For rotating the platform’s own privileged credentials and the restore steps after an incident, see Backup and restore.