Skip to content

Security: HawkinsOperations/hawkinsoperations-website

Security

SECURITY.md

Security Policy

Scope

This repository contains the public HawkinsOperations website. It is a public rendering surface for routing, documentation, and claim-bound summaries. Website rendering is not proof, and this policy does not imply managed monitoring, production support, runtime response coverage, service-level commitments, or public-safe runtime proof.

Reporting

Do not post secrets, credentials, private paths, private hostnames, exploit details, sensitive operational data, or private environment details in public issues, pull requests, discussions, or comments.

If GitHub private vulnerability reporting is available for this repository, use that route for sensitive reports. If it is not available, open a sanitized public issue that withholds sensitive details and provides only enough non-sensitive context to route the report.

Public Claim Boundary

Reports, fixes, and website changes must preserve the public claim boundary:

  • Website rendering is not proof.
  • Public ceiling remains CONTROLLED_TEST_VALIDATED unless separately approved.
  • Public-safe state remains NOT_PUBLIC_SAFE unless separately approved.
  • Runtime-active, signal-observed, production-ready, public-safe runtime proof, autonomous SOC, AI-approved disposition, analyst-approved disposition, and customer or enterprise deployment claims must not be introduced by website hygiene work.

There aren't any published security advisories