Skip to content

Security: rushilrawat/CapitolWatch

Security

SECURITY.md

Security Policy

CapitolWatch has a small security surface by design: the API is read-only (GET endpoints over already-public data), the pipeline runs as a local batch job, and there is no authentication, no user accounts, and no private data anywhere in the system. Everything it stores is public record.

Still, if you find something — a way to make the API write, a path traversal in the evidence-chain file handling, a scraper behavior that could harm a source site, or a dependency issue — please report it privately:

Please do not open a public issue for anything you believe is exploitable. You can expect an acknowledgment within a week. There is no bug bounty — this is an open-source research project — but reports are credited in the fix commit unless you prefer otherwise.

Data-integrity reports

A different kind of "vulnerability" matters just as much here: anything that could make the system state a wrong number — an extraction gap, a resolution mismatch, a statistical error. Those are welcome as public issues (use the bug template and include the filing's document ID), because the whole design goal is that wrong answers fail loudly.

There aren't any published security advisories