DTVSS Security Policy Search Calculator Calibration About Tiers Security

Security Policy

How to report vulnerabilities in DTVSS, what is in scope, and what to expect after you report. This policy is published in machine-readable form at /.well-known/security.txt in line with RFC 9116.

How to Report a Vulnerability

Report vulnerabilities privately through GitHub Security Advisories. Open the Security tab of the DTVSS repository and choose Report a vulnerability. Only repository maintainers will see the report.

Please do not open public GitHub issues, post on social media, or share proof-of-concept code publicly until a fix has shipped and we have agreed on a disclosure date.

What to Include in a Report

A working exploit is not required. A credible explanation of impact is enough to start triage.

Scope

IN SCOPE

OUT OF SCOPE

Safe Harbour

We will not pursue legal action against researchers who:

If in doubt, ask first via a private advisory.

Coordinated Disclosure Timeline

Acknowledgement Within 5 business days
Triage & severity assessment Within 10 business days
Fix or mitigation Within 90 days for high & critical
Public disclosure By mutual agreement

If we go quiet for more than 14 days without explanation, you may escalate by re-pinging the advisory or, as a last resort, disclosing publicly with reasonable notice.

Acknowledgements

Researchers who report valid issues and want public credit are listed in the closed advisories on the GitHub Security tab.

Self-audit history

We periodically run automated security scanners against the production site and remediate findings. Scan reports and remediation evidence are retained in a private audit repository.

Nikto v2.6.0 9 May 2026 - 0 critical/high; 2 low remediated
Nuclei v3.x 9 May 2026 - 0 medium/high/critical findings
OWASP ZAP baseline Continuous - nightly via GitHub Actions
Dependency CVE scanning pip-audit + Safety, daily + on every push

Next scheduled review: November 2026, or sooner if significant changes ship.

Policy Metadata

Last updated: 9 May 2026
Policy expires: 9 May 2027
Machine-readable: /.well-known/security.txt
Standard: RFC 9116
Preferred languages: English