Security
Custodexa’s job is to preserve evidence for other systems; we treat its own security issues as the highest priority.
Reporting channels
Section titled “Reporting channels”- GitHub private vulnerability reporting (preferred): open a private report via the main repository’s security advisories; details stay private.
- Email: security@custodexa.org.
Please include reproduction steps, an impact assessment, and the version you tested against.
Disclosure principles
Section titled “Disclosure principles”- Please do not disclose unpatched vulnerability details in public issues.
- We confirm receipt, keep you updated on progress, and coordinate the public disclosure timing with you after a fix ships.
- The full policy lives in the main repository’s SECURITY.md (English is authoritative; a Traditional Chinese version ships alongside).