-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #10 from mobilecoinofficial/feature/security-policy
add security policy
- Loading branch information
Showing
2 changed files
with
25 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -8,3 +8,5 @@ bin/ | |
.direv/ | ||
.direnv/ | ||
*.tgz | ||
|
||
*~ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
# Security Audits and Analyses | ||
|
||
We greatly welcome security audits and analysis of our projects. | ||
|
||
We are happy to work with you in assessing potential issues and in | ||
developing effective secure solutions. | ||
|
||
Should you find anything of concern, please feel free to email us at | ||
[security@mobilecoin.com](mailto:security@mobilecoin.com). We | ||
appreciate responsible disclosure and are happy to collaborate on | ||
timed announcements to credit you for your research discovery. | ||
|
||
## Out of Scope | ||
|
||
Anything in `/vendor` is out-of-scope from our perspective, although | ||
we are happy to help coodinate talking to the respective parties in | ||
control of upstream maintenance of works and/or libraries which we | ||
depend upon. | ||
|
||
Also out-of-scope is hardware security issues with particular devices. | ||
For example, should a certain chipset utilised by a vendor be subject | ||
to timing attacks, fault injection attacks, etc., this is not within | ||
scope. |