Skip to content

Security: nemarOrg/website

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Preferred: use GitHub's private vulnerability reporting ("Report a vulnerability" under the Security tab of the affected repository). Alternatively, email feedback@nemar.org with the subject line SECURITY.

Include the affected repository or service, steps to reproduce, and the impact you believe it has. We will acknowledge your report within 5 business days and keep you informed as we investigate and fix.

Scope

NEMAR services (api.nemar.org, data.nemar.org, nemar.org, docs.nemar.org) and the code in the nemarOrg repositories. Reports involving possible exposure of user account data or re-identifiable participant data are treated with the highest priority; those may also be sent to privacy@nemar.org.

Please act in good faith: do not access other users' data, degrade the service, or exfiltrate data beyond the minimum needed to demonstrate the issue.

There aren't any published security advisories