Skip to content

Security: L930861/Geosite

Security

SECURITY.md

Security Policy

GeoSite is currently a public demonstration. Do not submit secrets, personal sensitive information, unpublished business plans, or third-party personal information.

Reporting a vulnerability

Before formal commercial launch, the operator must publish a monitored security contact and response SLA. Until that channel exists, do not disclose an exploitable vulnerability publicly. Record the affected URL, request ID, impact, reproduction steps, and the minimum evidence needed to verify the issue.

Response targets

  • Critical vulnerability acknowledgement: 24 hours
  • High severity acknowledgement: 2 business days
  • Public disclosure only after a fix or an agreed disclosure date

Scope

The public website, its API routes, authentication when introduced, report generation, payment when introduced, and handling of external map and model credentials are in scope.

There aren't any published security advisories