Skip to content

Security: dotpenlabs/dotpen

SECURITY.md

Security Policy

Dotpen tries to keep your data as safe as possible, and does NOT sell any of your data to anyone.

Reporting a Vulnerability

If you discover a security vulnerability, please follow these steps:

  • DO NOT disclose the vulnerability publicly.
  • Report the issue on our GitHub Security page
  • If possible, provide a proof of concept or a way to reproduce the vulnerability.
  • If you have a fix, please send it to us.

We will respond to your report as soon as possible.

Thank you for helping us keep Dotpen safe and secure!

Vulnerability Disclosure Policy

When the security team receives a security vulnerability report, they will assign it to a primary handler. This person will coordinate the fix and release process, involving the following steps:

  • Confirm the problem and determine the affected versions.
  • Audit code to find any potential similar problems.
  • Prepare fixes for all releases still under maintenance. These fixes will be released as fast as possible.

There aren’t any published security advisories