Skip to content

Latest commit

 

History

History
14 lines (11 loc) · 623 Bytes

File metadata and controls

14 lines (11 loc) · 623 Bytes

Security policy

Reporting a vulnerability

Email security@instanode.dev with details (steps, scope, impact). SLA: 72h initial acknowledgement, 30 days for P0/P1 fix, 90-day coordinated disclosure. No paid bounty currently — service credits for verified P0/P1 reports.

Scope

In scope: this repository's source, https://api.instanode.dev, https://instanode.dev. Out of scope: third-party integrations (Razorpay, Brevo, DigitalOcean).

Safe harbor

Good-faith research that doesn't compromise customer data, doesn't disrupt service, and follows coordinated disclosure is safe from legal action under this policy.