Skip to content

Security: Envision-Construction/Open-OS

SECURITY.md

Security Policy

Supported Versions

We support the latest release of each repository on the main branch. Older branches and tagged releases are patched on a best-effort basis.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Report security issues privately via one of the following:

  1. Preferred: Private vulnerability reporting on the affected repository.
  2. Email: security@envisionconstruction.com — PGP key available on request.

Include, if possible:

  • Repository and branch/commit affected
  • A reproducible proof of concept
  • Impact assessment (what can an attacker do?)
  • Any suggested remediation

What to expect

Stage SLA
Acknowledgement within 2 business days
Initial triage + severity rating within 5 business days
Fix or mitigation plan within 30 days for critical, 90 days for high/medium
Public disclosure (coordinated) after fix is deployed

Scope

In scope:

  • All repositories under the Envision-Construction organization
  • Deployed services under *.envisionconstruction.com and *.envsn.com
  • Official NPM and PyPI packages published by Envision

Out of scope:

  • Social engineering of employees or contractors
  • Physical attacks against Envision infrastructure
  • Denial-of-service attacks (please do not test in production)
  • Third-party services we integrate with (report to them directly)

Safe harbor

We will not pursue legal action against researchers who:

  1. Make a good-faith effort to avoid privacy violations, data destruction, and service disruption
  2. Report vulnerabilities promptly through the channels above
  3. Do not exploit the issue beyond what is necessary to demonstrate it
  4. Give us a reasonable time to remediate before disclosure

Thank you for helping keep Envision and our customers safe.

There aren't any published security advisories