Skip to content

Security: zoecyber001/APCAF

Security

SECURITY.md

Security Policy

1. Reporting Security Vulnerabilities

If you discover a software vulnerability in APCAF tools, website code, or build scripts, please report it privately:

  • Email: maintainers@apcaf.org (or open a private security advisory on GitHub)
  • Response Target: Initial acknowledgment within 48 hours, with status updates every 5 business days until resolution.

Please do not open public issues for undisclosed vulnerabilities.

2. Reporting Inaccurate Assessment Content

APCAF maintains strict standards of technical accuracy and evidence integrity. If you identify:

  • A technical inaccuracy in a technique specification or building code citation,
  • An unverified exploit claim or overreach,
  • A miscategorized synthetic demonstration,

Please open a standard GitHub Issue or submit a pull request with corrective citations.

3. Scope

APCAF Base is a non-invasive physical security assessment specification. It does not provide offensive exploitation scripts, weaponized hardware firmware, or bypass execution tooling. Reports regarding the absence of offensive exploit code are considered out of scope.

There aren't any published security advisories