Skip to content

Security: Ghalbeyou/netconnect-io

Security

SECURITY.md

netConnect-io Security Guidelines

The security of our users and their data is of utmost importance to us at netConnect-io. We appreciate the vigilance of the community in identifying and reporting security vulnerabilities responsibly. To ensure the continued security of our software, we have established the following guidelines for reporting security-related issues.

Reporting Security Vulnerabilities

If you discover a security vulnerability in netConnect-io, please report it to our security team immediately by opening an issue here https://github.com/Ghalbeyou/netconnect-io/issues. Please provide as much detail as possible, including a description of the vulnerability, the steps to reproduce it, and any potential impact.

We request that you do not disclose the vulnerability publicly until it has been resolved and an appropriate announcement has been made. This allows us to investigate and address the issue before it becomes a threat to our users.

Responsible Disclosure

We appreciate responsible and coordinated disclosure of security vulnerabilities. We commit to:

  • Promptly acknowledging receipt of your vulnerability report.
  • Investigating and verifying the reported vulnerability.
  • Keeping you informed of the progress towards resolving the issue.
  • Providing credit and recognition for responsible disclosure, unless you request to remain anonymous.

Bug Bounty Program

As a token of our appreciation for the security research community, netConnect-io maintains a bug bounty program. If you discover a qualifying security vulnerability and report it responsibly, you may be eligible for a monetary reward.

Exclusions

The following activities are not considered in scope of our bug bounty program:

  • Social engineering attacks, including phishing, vishing, or smishing attacks.
  • Denial of service (DoS or DDoS) attacks or brute force attacks.
  • Attacks or vulnerabilities that only affect outdated or unsupported browsers or platforms.
  • Vulnerabilities in third-party libraries or dependencies that are not directly related to netConnect-io.

Legal Safe Harbor

We commit to not take legal action against security researchers who follow these guidelines in reporting security vulnerabilities in accordance with the responsible disclosure process.

Thank you for helping us ensure the security of netConnect-io and its users. We value your contributions in keeping our software safe and secure.

There aren’t any published security advisories