If you discover a software vulnerability in APCAF tools, website code, or build scripts, please report it privately:
- Email: maintainers@apcaf.org (or open a private security advisory on GitHub)
- Response Target: Initial acknowledgment within 48 hours, with status updates every 5 business days until resolution.
Please do not open public issues for undisclosed vulnerabilities.
APCAF maintains strict standards of technical accuracy and evidence integrity. If you identify:
- A technical inaccuracy in a technique specification or building code citation,
- An unverified exploit claim or overreach,
- A miscategorized synthetic demonstration,
Please open a standard GitHub Issue or submit a pull request with corrective citations.
APCAF Base is a non-invasive physical security assessment specification. It does not provide offensive exploitation scripts, weaponized hardware firmware, or bypass execution tooling. Reports regarding the absence of offensive exploit code are considered out of scope.