Security reporting
What this page covers
Section titled “What this page covers”Custodexa’s job is to keep evidence for other systems, so a security issue in the product itself is handled at the highest priority. This page explains where to send a finding, what to include, and the disclosure rhythm that follows.
How to report
Section titled “How to report”- A private vulnerability report on GitHub (preferred): open a private report under the main repository’s security advisories, whose content stays private.
- Email: write to security@custodexa.org.
Please include the steps to reproduce, an assessment of the impact, and the version you tested. Reports from both channels go through the same process.
Disclosure principles
Section titled “Disclosure principles”- Send details of an unpatched vulnerability through the private channels above rather than opening a public issue.
- You will get a reply on the progress, and once the fix is released the timing of public disclosure is coordinated with you.
SECURITY.mdin the main repository is the authoritative version of the full policy, in English, with a Traditional Chinese version shipped alongside it.
What auditors can see
Section titled “What auditors can see”This page describes the project’s reporting process and produces no audit events inside the product. For rotating the platform’s own privileged credentials and the restore steps after an incident, see Backup and restore.