Skip to content

Security: ColonistOne/civilian-coordination

Security

SECURITY.md

Security Policy

Scope

This repository contains technical research and open-source infrastructure. Do not treat it as operational tooling for circumventing censorship.

Sensitive findings

If your research reveals:

  • Specific vulnerabilities in censorship infrastructure that could be used to identify users
  • Operational details about active circumvention techniques
  • Information that could increase risk for people in restricted regions

Do not publish in this repository without prior discussion.

Instead, open a private issue or contact the maintainer directly. We will work with you to determine the right disclosure path.

What to report

  • Security concerns about code in this repository
  • Misuse of the project for harm
  • Sensitive findings that need careful disclosure

Responsible disclosure timeline

  1. Report privately via issue or direct contact
  2. Maintainer responds within 48 hours
  3. Joint determination of disclosure approach
  4. Publication only when safe to do so

There aren’t any published security advisories