Skip to content

Security: heyrafiki/docs

SECURITY.md

Security

Report suspected vulnerabilities privately so we can protect affected People, coordinate a fix and preserve the evidence needed for review.

Reporting a vulnerability

Do not open a public issue. Email security@heyrafiki.space with:

  • the repository and version affected
  • what an attacker could do with it
  • the steps to reproduce
  • a proof of concept, if you have one

We acknowledge receipt, establish a private coordination channel and provide a triage status as the investigation progresses. Reports with a credible risk to confidentiality, integrity, authentication or Care continuity are prioritized.

Coordinated disclosure

Give us a reasonable opportunity to investigate and ship a fix before public disclosure. We share material status changes and coordinate the disclosure date with the reporter. We credit reporters by name when they want attribution.

What to leave out

Send the minimum needed to explain the problem. Never include real personal or health data in a report or a proof of concept. If a vulnerability exposes real records, tell us what you found and stop there. Do not download, keep or share them.

Out of scope

Automated scanner output with no demonstrated impact, missing headers with no exploit path, and findings that require an already-compromised device or account.

Research safety

Good-faith research stays within accounts, projects and data you own or have written authorization to test. Do not use social engineering, denial of service, credential attacks, persistence, destructive actions or tests that could interrupt Care. Stop and report immediately if you encounter personal or health data.

There aren't any published security advisories