Skip to content

Security: JuanCS-Dev/protovolt

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Email us at: juan@vertice-maximus.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect

  • Response Time: Within 48 hours
  • Resolution: We aim to resolve critical issues within 7 days
  • Disclosure: We will coordinate disclosure with you

Scope

The following are in scope:

  • Authentication/Authorization bypasses
  • Data exposure
  • XSS, CSRF, SQL Injection
  • Remote code execution

Out of Scope

  • Denial of Service (DoS)
  • Social engineering
  • Physical security

Security Best Practices

This project follows:

  • OWASP Top 10 guidelines
  • Firebase Security Rules for data protection
  • Environment variables for sensitive configuration
  • No secrets in client-side code

Acknowledgments

We appreciate responsible disclosure and will acknowledge security researchers who help improve our security.

There aren’t any published security advisories