Security · Disclosure
Security & responsible disclosure.
NullRabbit OSS is security software, but like any code it can have bugs or vulnerabilities. We take responsible disclosure seriously and ask that you follow these guidelines.
[01]·How to report
Private email first.
- →Please report security issues privately via email at [email protected].
- →Do not open public GitHub issues for sensitive findings.
[02]·What to include
A clear, reproducible report.
- →A clear description of the issue.
- →Steps to reproduce, if possible.
- →Any potential impact you see.
[03]·Our commitment
Acknowledged within 72 hours.
- →We aim to acknowledge reports within 72 hours.
- →We will provide a timeline for remediation where applicable.
- →Once a fix is available, we may credit reporters (optional).
[04]·Scope
All NullRabbit OSS repositories.
This policy applies to all NullRabbit OSS repositories under the nullrabbitlabs organization, including scanners, orchestrators, data models, and research repos.
[05]·License & trademark
MIT for code. Trademark held.
- →Code is released under the MIT License.
- →"NullRabbit" is a trademark of Polkaspots Ltd.
