Email security@ummat.dev. PGP key forthcoming.
- 48 hours: initial triage and acknowledgement
- 7 days: patch for HIGH severity
- 30 days: patch for MEDIUM severity
In scope: code in this repository. Out of scope: third-party dependencies (report upstream), denial-of-service via volumetric attacks, social engineering.
Coordinated disclosure preferred. Do not publish details until a patch is shipped or 90 days have passed, whichever is sooner.