Skip to content

Security: aec-platform/sodo-dd

Security

docs/SECURITY.md

Security policy

Reporting a vulnerability

Email security@sodo-dd.vn with a description, reproduction steps, and your PGP key. We acknowledge within 2 business days and aim for resolution within 30 days of triage.

Please do not file public GitHub issues for security bugs.

Scope

In scope: this repository (api, worker, web), the deployed production environment at *.sodo-dd.vn, and the published API.

Out of scope:

  • Third-party partner systems (dichvucong.gov.vn, provincial portals) — report directly to those operators.
  • Denial-of-service via volumetric attack.
  • Findings that require physical access to user devices.

Safe harbor

We will not pursue legal action against good-faith security researchers who:

  1. Make a reasonable effort to avoid privacy violations and disruption.
  2. Do not exfiltrate data beyond what is necessary to demonstrate the issue.
  3. Give us reasonable time to remediate before public disclosure.

There aren't any published security advisories