Skip to content

Security: WaypointCA/shieldcv

Security

SECURITY.md

Security Policy

Supported Versions

ShieldCV supports the current main branch.

Reporting a Vulnerability

Please report security issues to security@shieldcv.app.

Best effort response time is within 72 hours.

Please include:

  • A description of the issue
  • Steps to reproduce
  • Affected files, routes, or packages if known
  • Any proof of concept or logs that help explain impact

Scope

This policy covers:

  • The ShieldCV web application
  • All packages in this monorepo
  • Deployment and security configuration that ships with the repository

Out of Scope

This project does not offer a bug bounty program.

Issues caused solely by:

  • A compromised local operating system
  • Malicious browser extensions
  • User-selected weak passphrases
  • Third-party services outside this repository

may still be useful to report, but they are outside the core application security boundary.

There aren’t any published security advisories