Skip to content

Security: naust-mail/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report security vulnerabilities privately via GitHub Security Advisories on the repository the issue affects:

If you are unsure which repo an issue belongs to, report it against naust-mail/naust and it will be redirected.

Do not open a public issue for a security vulnerability.

Threat model and hardening details

naust-mail/naust has a full security guide covering the threat model, TLS configuration, brute-force protection, DNSSEC/DANE, and spam filtering for a running instance. This org-level policy only covers how to report an issue - see that document for what a configured box actually protects against.

There aren't any published security advisories