This policy covers every public repository in the ADAvault organisation, and adavault.com
and its API. A repository that publishes its own SECURITY.md takes precedence.
Report privately through GitHub. Please do not open a public issue.
- For code in a repository: open that repository's Security tab and choose Report a vulnerability.
- For adavault.com, its API, or anything not tied to one repository: use the Security tab of ADAvault/.github.
Tell us what you found, where it is, how to reproduce it, and the impact you expect.
We assess every report against the code and against how it is deployed. We will contact you through the advisory if we need more detail, and again when a fix is released. Only the latest release of each project is supported.
ADAvault does not run a bug bounty and does not pay for reports. Reports that ask for payment, or that forward automated scanner output without a demonstrated impact, are assessed but not answered.
Denial of service, social engineering, physical attacks, and third-party services we use.