diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..0d0a790 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,28 @@ +# Security Policy + +This repository contains Permission Protocol documentation, the reference demo, and CI templates. + +## Reporting a vulnerability + +**Do not open public issues for security vulnerabilities.** + +Email: security@permissionprotocol.com + +Include a description, steps to reproduce, and your assessment of impact. We acknowledge reports within 48 hours and keep you informed through resolution. + +Machine-readable contact: https://www.permissionprotocol.com/.well-known/security.txt + +## Safe harbor + +We will not pursue or support legal action against good-faith security research that: + +- respects user privacy and does not access, modify, or destroy data that is not yours; +- avoids service disruption (no denial of service, no spam); +- gives us reasonable time to remediate before public disclosure. + +If you are unsure whether something is in scope, ask first at the address above. + +## Notes + +- There is no formal bug bounty program today. With your permission, we credit reporters in release notes. +- Our security and compliance posture is published at https://www.permissionprotocol.com/trust.