CapitolWatch has a small security surface by design: the API is read-only (GET endpoints over already-public data), the pipeline runs as a local batch job, and there is no authentication, no user accounts, and no private data anywhere in the system. Everything it stores is public record.
Still, if you find something — a way to make the API write, a path traversal in the evidence-chain file handling, a scraper behavior that could harm a source site, or a dependency issue — please report it privately:
- Preferred: open a private report via GitHub Security Advisories.
- Or email: rawat.rushil.work@gmail.com with
[CapitolWatch security]in the subject.
Please do not open a public issue for anything you believe is exploitable. You can expect an acknowledgment within a week. There is no bug bounty — this is an open-source research project — but reports are credited in the fix commit unless you prefer otherwise.
A different kind of "vulnerability" matters just as much here: anything that could make the system state a wrong number — an extraction gap, a resolution mismatch, a statistical error. Those are welcome as public issues (use the bug template and include the filing's document ID), because the whole design goal is that wrong answers fail loudly.