Add Security Policy #1001

Merged
jonah merged 2 commits from security-policy into master 2019-07-09 11:52:20 +00:00
Owner

As recommended in #988:

Since privacytools.io has somewhat recently become a service provider, I suggest we have an official bug reporting policy.

This sounds good to me. I added some basic instructions to a security policy file, do you think this is enough or well-constructed? Let me know if anything should be added @beardog108.


Closes #988

As recommended in #988: > Since privacytools.io has somewhat recently become a service provider, I suggest we have an official bug reporting policy. This sounds good to me. I added some basic instructions to a security policy file, do you think this is enough or well-constructed? Let me know if anything should be added @beardog108. --- Closes #988
Mikaela (Migrated from github.com) reviewed 2019-06-20 21:32:12 +00:00
blacklight447 (Migrated from github.com) reviewed 2019-06-20 21:32:12 +00:00
netlify[bot] commented 2019-06-20 21:32:55 +00:00 (Migrated from github.com)
Author
Owner

Deploy preview for privacytools-io ready!

Built with commit ad344be456

https://deploy-preview-1001--privacytools-io.netlify.com

Deploy preview for *privacytools-io* ready! Built with commit ad344be456504a6f309d860c1d280917f6f4f39d https://deploy-preview-1001--privacytools-io.netlify.com
ghost commented 2019-06-20 21:40:32 +00:00 (Migrated from github.com)
Author
Owner

Thanks for adding. Looks pretty good, but i'd clarify that user & admin accounts not owned by the tester are out of scope as well.

Thanks for adding. Looks pretty good, but i'd clarify that user & admin accounts not owned by the tester are out of scope as well.
ghbjklhv (Migrated from github.com) reviewed 2019-06-21 22:09:48 +00:00
@ -0,0 +20,4 @@
* Reports against infrastructure outside our control
* User or admin accounts not owned by the tester
## Disclosure Policy
ghbjklhv (Migrated from github.com) commented 2019-06-21 22:09:48 +00:00
Author
Owner

This does not seem to include if users will be informed in case data is leaked.

My understanding is that social.privacytools.io and other services collect information like email.
What happens if this information gets stolen? How would users be informed?

This does not seem to include if users will be informed in case data is leaked. My understanding is that social.privacytools.io and other services collect information like email. What happens if this information gets stolen? How would users be informed?
jonah reviewed 2019-06-22 00:14:07 +00:00
@ -0,0 +20,4 @@
* Reports against infrastructure outside our control
* User or admin accounts not owned by the tester
## Disclosure Policy
Author
Owner

Added info to ad344be

Added info to ad344be
jonah approved these changes 2019-06-22 06:59:48 +00:00
privacytoolsIO (Migrated from github.com) approved these changes 2019-07-09 11:52:12 +00:00
This repo is archived. You cannot comment on pull requests.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1001
No description provided.