VULNERABILITY DISCLOSURE

Security PolicyWe take security seriously. Here is how we handle disclosures.

Reporting a Vulnerability

If you believe you have found a security vulnerability in SOCRoot's public website or repositories, please report it privately. Reports are reviewed and prioritized according to reproducibility, impact, and the maturity of the affected component.

  • Submit your report via our Contact Page.
  • Do not disclose the vulnerability publicly until we have had a chance to remediate it.
  • Provide clear, reproducible steps or a proof of concept (PoC).

Our Commitment

Triage

Reports are prioritized according to reproducibility, impact, and affected-component maturity; no public response window is promised.

Safe Harbor

We will not pursue legal action against researchers who follow this policy in good faith.

Transparency

We will keep you informed of the progress as we investigate and mitigate the issue.

Remediation

We prioritize fixing confirmed vulnerabilities based on severity and impact.

Out of Scope

The following activities are strictly prohibited and out of scope:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
  • Physical testing of our facilities or hardware.
  • Social engineering (e.g., phishing or vishing) against any person associated with the project.
  • Exfiltrating, destroying, or modifying data that does not belong to you.
  • Automated scanning with tools that generate extensive traffic.

Submit a Report

Found something? Let us know securely and directly.

Contact Security Team