Skip to content

Security: ToppyMicroServices/toppymicroservices.github.io

SECURITY.md

Security Policy

This repository hosts the public website for ToppyMicroServices OÜ.

For the full coordinated disclosure policy, see:

Machine-readable policy:

Scope

In scope:

  • Public assets under toppymicros.com
  • Public GitHub repositories under ToppyMicroServices

Out of scope (non-exhaustive):

  • Best-practice suggestions without a demonstrable exploit path
  • Self-XSS and browser/devtools-only issues
  • Volumetric denial of service

Reporting a Vulnerability

Please report vulnerabilities to:

Include:

  1. Affected asset and vulnerability summary
  2. Reproduction steps / PoC
  3. Impact assessment
  4. Optional remediation guidance

Response Targets

  • Acknowledgement target: within 5 business days
  • Remediation target: generally 30 days; complex issues may require up to 60 days

Safe Harbor

If you act in good faith and follow the policy, we will not pursue legal action for your research activities.

There aren’t any published security advisories