NullRabbit
Security · Disclosure

Security & responsible disclosure.

NullRabbit OSS is security software, but like any code it can have bugs or vulnerabilities. We take responsible disclosure seriously and ask that you follow these guidelines.

[01]·How to report

Private email first.

  • Please report security issues privately via email at [email protected].
  • Do not open public GitHub issues for sensitive findings.
[02]·What to include

A clear, reproducible report.

  • A clear description of the issue.
  • Steps to reproduce, if possible.
  • Any potential impact you see.
[03]·Our commitment

Acknowledged within 72 hours.

  • We aim to acknowledge reports within 72 hours.
  • We will provide a timeline for remediation where applicable.
  • Once a fix is available, we may credit reporters (optional).
[04]·Scope

All NullRabbit OSS repositories.

This policy applies to all NullRabbit OSS repositories under the nullrabbitlabs organization, including scanners, orchestrators, data models, and research repos.

[05]·License & trademark

MIT for code. Trademark held.

  • Code is released under the MIT License.
  • "NullRabbit" is a trademark of Polkaspots Ltd.