Skip to content

Security: tjsasakifln/SmartLic

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
v0.5.x (current)
< v0.5

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Report security issues by emailing: tiago.sasaki@confenge.com.br

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact assessment
  • Your suggested fix (if any)

We will acknowledge receipt within 48 hours and aim to release a fix within 7 days for critical issues.

Scope

In scope:

  • smartlic.tech and all subdomains
  • SmartLic API endpoints
  • Authentication and authorization bypasses
  • Data exposure vulnerabilities

Out of scope:

  • Denial of service attacks
  • Social engineering
  • Physical security
  • Third-party services (Supabase, Railway, Stripe)

There aren't any published security advisories