Skip to content

Security: hyvor/dev

Security

SECURITY.md

Security Policy

This repository is the starting point for HYVOR development and contains our other repositories as submodules (see README.md), covering both our open-source and proprietary products.

Reporting a Vulnerability

If you discover a security vulnerability in any HYVOR product or in this repository's development tooling, please report it privately to:

security@hyvor.com

You can encrypt your message using our PGP key, available at hyvor.com/gpg.txt.

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

When reporting, please include as much of the following as you can:

  • A description of the vulnerability and its potential impact.
  • The product/repository and version or commit affected.
  • Steps to reproduce, or a proof-of-concept.

What to expect

We will acknowledge your report as soon as we can and work with you to understand and address the issue. Please give us reasonable time to investigate and fix a vulnerability before disclosing it publicly.

We are open to third-party security audits and penetration tests; contact us at the address above to coordinate.

Scope

This policy applies to all HYVOR-owned repositories, including those listed as submodules in README.md, whether open-source or proprietary, as well as our hosted products (Hyvor Talk, Hyvor Blogs, Hyvor Post, Fortguard, etc.).

See hyvor.com/security for more on our security practices (encryption, infrastructure, certifications, and Enterprise security documentation).

There aren't any published security advisories