This policy applies to all branches of the lafiya-web repository.
Please report security issues privately via one of the following methods:
- GitHub Private Security Advisory: Open a private advisory through the repository's "Security" tab.
- Email: Send details to
security@lafiya-xyz.org(encrypted email preferred).
In‑scope:
- Security vulnerabilities in the web application code, including authentication, RLS, and attestation handling.
- Disclosure of any private data handling or cryptographic implementations.
Out‑of‑scope:
- Issues related to third‑party services (Supabase, Stellar network) unless they directly affect the repository.
We aim to acknowledge receipt of a report within 48 hours and provide a full response within 14 days. Critical vulnerabilities will be prioritized.
We request that you do not publicly disclose details of the vulnerability until a fix has been released.
This policy is aligned with the Digital Public Goods standards and the Nigeria Data Protection Act.