keyrotate

Vulnerability Disclosure Policy

Document 03 of 5 · Last reviewed:

If you have found a security issue in keyrotate, thank you for taking the time to report it. This document explains how to do so safely, what we consider in scope, and what to expect after you report.

How to report

Use the GitHub Security Advisories form on the keyrotate repository — it lets you file a confidential report that only project maintainers can see:

Report a vulnerability →

If you cannot use GitHub Advisories, email security@keyrotate.dev with the details. Please do not open a public GitHub issue for a security report.

What to include

What is in scope

What is out of scope

Response timeline

Recognition

We will credit you in the security advisory and the release notes unless you prefer to remain anonymous. There is no monetary bug bounty at this time — this is a free open-source project run by a single maintainer.

Safe harbor

We will not pursue legal action against good-faith security research that follows this policy. "Good faith" means: you do not access data that isn't yours, you do not perform DoS testing on production infrastructure, you do not retain any secrets you may encounter during testing, and you give us a reasonable opportunity to fix the issue before public disclosure.