This policy applies to repositories maintained by IT Custom Solution LLC that do not publish a more specific security policy.
Use the affected repository's Security → Report a vulnerability option to submit a private vulnerability report. If that option is unavailable, contact hello@itcustomsolution.com to arrange a private reporting channel. Send only the affected repository name and a brief description in the initial email.
Do not post exploitable details, credentials, customer data, or personal information in a public issue or pull request. Do not include real credentials or customer records in a report. A minimal reproduction using synthetic data is preferred.
Include the affected version or commit, expected and observed behavior, impact, and safe reproduction steps. Testing must remain within systems and accounts you are authorized to use; this policy does not authorize access to other accounts or production data.
Repository-specific support statements take precedence. An archived repository or a repository labeled retired is retained for historical purposes and should not be assumed to receive security updates. An open dependency alert is not evidence that a fix has reached an installed application or production service.
ITC will assess the report, coordinate remediation where applicable, and communicate through the private reporting channel. This policy does not promise a response deadline, bounty, or authorization for intrusive testing.