Docs / Project

Security policy

Araldo holds credentials that can post as other people's accounts. We take reports seriously and appreciate responsible disclosure.

Reporting a vulnerability

Do not open a public issue. Report privately through GitHub's private vulnerability reporting.

Please include the affected version or commit, a description of the impact, and steps to reproduce. Never include real platform credentials.

We aim to acknowledge reports within 3 business days and to agree on a fix and disclosure timeline within 10 business days.

Supported versions

Until 1.0, only the latest release receives security fixes.

Operator responsibilities

Araldo is software you run. Operators are responsible for TLS, keeping the master keys (ADR 0008) outside the database and backed up, database encryption at rest, and network controls.

Edit this page on GitHub