Skip to content

Security: Grootsingh/TheTechCommute

Security

SECURITY.md

TechCommute Security Policy

Reporting a Vulnerability

Reporting a Vulnerability

We take the security of our software at TechCommute very seriously. If you have discovered a security vulnerability in our software, we urge you to inform us immediately. We are committed to investigating all legitimate reports and working diligently to fix any issues promptly.

How to Report a Vulnerability

  1. Do Not Publicly Disclose: Public disclosure of a vulnerability can put the entire community at risk. If you discover a security issue, please keep it confidential and allow us to address it.

  2. Contact: Directly message either Jason Torres or Jacob Ashley in X. Please provide as much information as possible about the vulnerability, including as many of the following as possible, descriptions, proof-of-concept, steps to reproduce, and an impact analysis.

  3. Timing: After reporting a vulnerability, please allow us a reasonable amount of time to resolve the issue before disclosing it to others.

  4. Anonymous Reporting: If you wish to remain anonymous, consider using a "burner" account in X. Further down the line we might consider opening an email account for reports like this. In that case you can always use something like Protonmail for anonymous emails.

Our Commitment

When you report a vulnerability to us, we commit to:

  • Acknowledging receipt of your report.
  • Providing an estimated timeframe for addressing the report.
  • Notifying you when the vulnerability has been fixed.

We value your contributions in keeping our project secure and extend our gratitude to the security research community for their responsible disclosure practices.

Jason Torres & Jacob Ashley

There aren’t any published security advisories