Skip to content

Security: bxn-dev/surface

Security

SECURITY.md

Security policy

Please report vulnerabilities privately through GitHub Security Advisories for this repository. Do not open a public issue containing exploit details or sensitive target data.

Include the affected version, impact, reproduction steps using local fixtures where possible, and a proposed mitigation. Maintainers will acknowledge a complete report as soon as practical.

Surface is for authorized assessment only. Reports about unauthorized scanning campaigns belong with the relevant service provider or authorities, not this project's vulnerability channel.

Protect databases and signing keys with least privilege and mode 0600. Close processes using a database before restore and verify every backup.

There aren't any published security advisories