Skip to content

Security: modarresi1913/Evoguard

Security

SECURITY.md

EvoGuard Security Policy

πŸ›‘οΈ Supported versions

EvoGuard is currently in the MVP / design-partner pilot phase. Only the latest commit on main is supported with security fixes.

Version Supported
main (latest) βœ…
Tagged releases βœ… (when available)
Older commits ❌

πŸ“¨ Reporting a vulnerability

We take security vulnerabilities seriously. Please follow this process:

For critical / actively-exploitable vulnerabilities

Do NOT file a public issue. Instead, email security@evoguard.app with:

  1. A description of the vulnerability
  2. Steps to reproduce
  3. Affected components
  4. Proof of concept (encrypted if sensitive β€” use our PGP key below)

For lower-severity issues

Use the Security Report issue template. This is appropriate for:

  • Defense-in-depth suggestions
  • Hardening ideas
  • Theoretical concerns
  • Issues already documented in our working threat model

⏱️ Response timeline

Step Target SLA
Acknowledge receipt 24 hours
Initial assessment 72 hours
Triage & severity assignment 5 business days
Fix or mitigation plan 30 days (high), 90 days (medium), 180 days (low)
Coordinated public disclosure 90 days after fix released

πŸ” PGP key

For encrypted vulnerability reports, use the following PGP key:

EvoGuard Security <security@evoguard.app>
Fingerprint: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000

Note: The actual PGP key will be published before the production launch.

πŸ† Recognition

We acknowledge security researchers who responsibly disclose vulnerabilities:

  • Hall of Fame β€” listed on our security page (with permission)
  • Swag β€” EvoGuard sticker pack + t-shirt for confirmed high-severity reports
  • Bounty β€” monetary rewards for critical vulnerabilities in production (after launch)

πŸ“‹ Scope

In scope

  • The EvoGuard demo dashboard (github.com/modarresi1913/Evoguard)
  • Production backend components (when available)
  • The GitHub App integration
  • The web dashboard
  • API endpoints
  • Authentication & authorization
  • Tenant isolation
  • Encryption implementation

Out of scope

  • Vulnerabilities in third-party dependencies (report to upstream maintainers)
  • Social engineering attacks against EvoGuard employees
  • Physical attacks against EvoGuard infrastructure
  • DoS attacks against the production service (use responsible disclosure)
  • Issues requiring physical access to a user's device
  • Bugs in unsupported versions

πŸ› οΈ Security measures we already have

See the Security & Privacy section of the README for our published working threat model and security policies.

πŸ“œ Coordinated disclosure

We follow Google's Project Zero disclosure guidelines:

  • 90-day disclosure deadline
  • Automatic publication of the vulnerability report after the deadline
  • Extensions granted on a case-by-case basis

πŸ“ž Contact

There aren't any published security advisories