diff --git a/security.md b/security.md new file mode 100644 index 0000000..955ed85 --- /dev/null +++ b/security.md @@ -0,0 +1,14 @@ +# Reporting Security Issues + +Contrast takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions. + +To report a security issue, please see our official [Vulnerability Disclosure Policy +](https://www.contrastsecurity.com/disclosure-policy) + +Contrast will send a response indicating the next steps in handling your report. After the initial reply to your report, the security team will keep you informed of the progress towards a fix and full announcement, and may ask for additional information or guidance. + +Report security bugs in third-party modules to the person or team maintaining the module. + +## Learning More About Security + +To learn more about securing your applications with Contrast, please see the [our docs](https://docs.contrastsecurity.com/?lang=en).