Skip to content

Security: antonio-ivanovski/spliit-cloud

Security

SECURITY.md

Security

Reporting a vulnerability

Do not open a public GitHub issue. Email security@spliit.cloud with:

  • description of the issue and impact
  • steps to reproduce or proof-of-concept
  • commit hash or version tested
  • your contact info

Expect acknowledgement within 72 hours, triage within 7 days, regular status updates, and credit in release notes (unless you prefer anonymity).

Scope

In scope: authentication/session bypass, authorization bypass, XSS/CSRF, injection, unsafe document handling, leaked secrets, supply-chain issues in production dependencies.

Out of scope: misconfigured self-hosted instances, social engineering, third-party service issues (OpenAI, Cloudflare, SMTP providers — report to them).

Disclosure

90-day coordinated disclosure by default. Shorter or longer windows discussed case by case.

There aren't any published security advisories