Skip to content

Security: TrustSignal-dev/TrustSignal-Verify-Artifact

SECURITY.md

Security Policy

Reporting A Vulnerability

Report suspected vulnerabilities privately to security@trustsignal.dev.

Include:

  • a clear description of the issue
  • reproduction steps
  • affected versions or commit references
  • impact assessment if known

Do not open public GitHub issues for suspected security vulnerabilities.

Sensitive Information

  • Do not include secrets, API keys, tokens, customer data, or private receipts in reports.
  • Sanitize logs, payloads, and screenshots before sharing them.

Responsible Disclosure

TrustSignal reviews reports as quickly as possible, validates impact, and coordinates remediation and disclosure timing with reporters when appropriate.

There aren’t any published security advisories