Skip to content

Security: nis2shield/infrastructure

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
v1.0.x
v0.3.x
< v0.3

Reporting a Vulnerability

Please report sensitive security issues via email to security@nis2shield.com or by opening a GitHub Security Advisory.

DO NOT create public GitHub issues for security vulnerabilities.

Security Updates & Mailing List

We proactively notify users about:

  • Critical security patches (CVEs)
  • NIS2/DORA regulatory updates affecting compliance logic
  • Major breaking changes
  • Enterprise Module updates (Disaster Recovery, etc.)

👉 Subscribe to Security Updates

Encryption Standards

All infrastructure configurations must adhere to:

  • Transport: TLS 1.2+ mandatory (TLS 1.3 preferred).
  • At Rest: AES-256 for all persistent storage.
  • Secrets: Encrypted via KMS/Vault, never committed.

Response Timeline

  1. Acknowledgment: Within 24 hours.
  2. Assessment: Within 72 hours.
  3. Patch: Critical issues patched within 7 days.

There aren’t any published security advisories