Skip to content

Security: Celo-HT/celoht-brand

SECURITY.md

Security Policy - CeloHT Brand Repository

Scope

This repository contains brand documentation, guidelines, and static SVG/image assets. It does not contain application code, smart contracts, or systems that process user funds or personal data. For security concerns related to CeloHT's smart contracts, dApp, or website, see the relevant repository at github.com/Celo-HT.

Reporting a Vulnerability or Brand Misuse

If you discover:

  • A security issue in the automation (e.g. GitHub Actions workflows) tied to this repository
  • Fraudulent use of the CeloHT logo or name (e.g. phishing sites, fake tokens using CeloHT branding, impersonation)
  • Malicious content submitted to this repository

Please report it privately rather than opening a public issue:

We will acknowledge reports within 5 business days and provide a resolution timeline.

Brand Misuse Is a Security Issue

Because CeloHT operates in the financial inclusion space, fraudulent use of the CeloHT name or logo (for example, to promote a fake token or phishing site) is treated as a security priority, not just a trademark matter. If you see CeloHT branding used to solicit funds, promote a token, or imply investment returns, report it immediately - this directly contradicts CeloHT's non-affiliation and non-investment status (see BRAND_GUIDE.md).

Supported Versions

This repository is documentation and static assets; there is no versioned "patching" model. The main branch always reflects the current, correct brand standard. Older tagged releases (see CHANGELOG.md) are kept for historical reference only and should not be treated as current guidance.

There aren't any published security advisories