Security

Responsible Disclosure

How to report a security vulnerability so it can be fixed before it's exploited.

  1. Home
  2. ›
  3. Responsible Disclosure

Scope

This applies to security issues affecting Digital World reference implementations (see the repositories under gitlab.com/digitalworld) or the core network infrastructure described in the Engineering Specification. Issues in a specific provider's own app or service should be reported to that provider directly - see Digital Providers.

How To Report

Channel Status
Dedicated security email Not yet published
PGP key for encrypted reports Not yet published
Vulnerability intake form Not yet published
Interim route: confidential GitLab issue Available today - open a confidential issue on the relevant repository under gitlab.com/digitalworld

Do not report a vulnerability through a public council meeting or any other public channel. Until a dedicated email and intake form are published, the confidential GitLab issue route above is the only channel we ask you to use. Include enough detail to reproduce the issue and a way to reach you.

What We Ask

  • Give us a reasonable opportunity to investigate and address an issue before any public disclosure.
  • Avoid accessing, modifying, or deleting data that isn't your own while testing.
  • Don't perform testing that could degrade service for other members.
  • Don't report a suspected vulnerability through a public channel, including council meetings.

Disclosure Policy

We ask for coordinated disclosure: please give the affected provider or reference implementation a reasonable opportunity to investigate and remediate before any public write-up. Because Digital World is an open network of independent providers rather than a single company, the exact disclosure timeline is agreed with you case by case for now, until a formal, published SLA replaces this interim approach.

Safe Harbor

If you make a good-faith effort to comply with the guidance on this page - including the Scope and What We Ask sections above - we will not pursue legal action against you for that research. This commitment does not extend to testing conducted outside this page's stated scope, testing that violates the What We Ask section, or access to a specific provider's systems without that provider's own authorization.

Bug Bounty

No paid bug bounty program is currently offered. Good-faith reports are still welcome and reviewed through the channel above.

Security Advisories

No security advisories have been published yet. Resolved, disclosed issues will be listed here going forward.

What To Expect

Reports are reviewed by the relevant provider or the network's governance councils. Formal acknowledgment and triage targets have not yet been published; until they are, response times vary since Digital World is an open network of independent providers rather than a single company - see Who Operates The Website.