From a171b9a2006a37a1510ddfb07e312833eab034a5 Mon Sep 17 00:00:00 2001 From: Claude Date: Tue, 25 Aug 2026 19:44:58 +0000 Subject: [PATCH] docs: add SECURITY.md (A2c) Disclosure path and safe harbor, landing across all Permission Protocol public repos. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01XPRcFvYLR6RS7vgJhYynrJ --- SECURITY.md | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..967b6d4 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,28 @@ +# Security Policy + +This repository contains pp, the offline Permission Protocol receipt verifier. + +## Reporting a vulnerability + +**Do not open public issues for security vulnerabilities.** + +Email: security@permissionprotocol.com + +Include a description, steps to reproduce, and your assessment of impact. We acknowledge reports within 48 hours and keep you informed through resolution. + +Machine-readable contact: https://www.permissionprotocol.com/.well-known/security.txt + +## Safe harbor + +We will not pursue or support legal action against good-faith security research that: + +- respects user privacy and does not access, modify, or destroy data that is not yours; +- avoids service disruption (no denial of service, no spam); +- gives us reasonable time to remediate before public disclosure. + +If you are unsure whether something is in scope, ask first at the address above. + +## Notes + +- There is no formal bug bounty program today. With your permission, we credit reporters in release notes. +- Our security and compliance posture is published at https://www.permissionprotocol.com/trust.