Skip to content

Security: SouthToxic/Lafiya-web

Security

SECURITY.md

Security Policy

Supported Versions / Branches

This policy applies to all branches of the lafiya-web repository.

Reporting a Vulnerability

Please report security issues privately via one of the following methods:

  • GitHub Private Security Advisory: Open a private advisory through the repository's "Security" tab.
  • Email: Send details to security@lafiya-xyz.org (encrypted email preferred).

Scope

In‑scope:

  • Security vulnerabilities in the web application code, including authentication, RLS, and attestation handling.
  • Disclosure of any private data handling or cryptographic implementations.

Out‑of‑scope:

  • Issues related to third‑party services (Supabase, Stellar network) unless they directly affect the repository.

Expected Response Time

We aim to acknowledge receipt of a report within 48 hours and provide a full response within 14 days. Critical vulnerabilities will be prioritized.

Responsible Disclosure

We request that you do not publicly disclose details of the vulnerability until a fix has been released.


This policy is aligned with the Digital Public Goods standards and the Nigeria Data Protection Act.

There aren't any published security advisories