This policy applies to all public repositories of the Prudai organisation that do not have their own SECURITY.md, and to the Prudai products and websites.
Email security@prudai.com. Please do not open a public issue, pull request or discussion for a security problem.
Include, where you can:
- the product, URL or repository and version affected;
- steps to reproduce, or a proof of concept;
- the impact as you see it.
Please give us reasonable time to fix the issue before you disclose it publicly. We prefer Dutch or English.
- Test only against your own accounts and data. Do not access, change or delete data of other users.
- No denial-of-service testing, social engineering or physical attacks.
- Stop and report as soon as you find access to data that is not yours.
Our machine-readable contact details are in security.txt. Security and compliance information is published at trust.prudai.com.