This repository is the starting point for HYVOR development and contains our other repositories as submodules (see README.md), covering both our open-source and proprietary products.
If you discover a security vulnerability in any HYVOR product or in this repository's development tooling, please report it privately to:
You can encrypt your message using our PGP key, available at hyvor.com/gpg.txt.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
When reporting, please include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- The product/repository and version or commit affected.
- Steps to reproduce, or a proof-of-concept.
We will acknowledge your report as soon as we can and work with you to understand and address the issue. Please give us reasonable time to investigate and fix a vulnerability before disclosing it publicly.
We are open to third-party security audits and penetration tests; contact us at the address above to coordinate.
This policy applies to all HYVOR-owned repositories, including those listed as submodules in README.md, whether open-source or proprietary, as well as our hosted products (Hyvor Talk, Hyvor Blogs, Hyvor Post, Fortguard, etc.).
See hyvor.com/security for more on our security practices (encryption, infrastructure, certifications, and Enterprise security documentation).