Cerin Amroth · Disclosure Policy security.txt

Vulnerability Disclosure Policy

We conduct good-faith security research and coordinated vulnerability disclosure.

We do not extort, sell access, retain sensitive data beyond what is necessary to demonstrate impact, deploy persistence, or disclose unresolved vulnerabilities before a reasonable remediation window has passed.

Reporting

Report a vulnerability to security@cerinamroth.com. Contact details, our encryption key, and this policy are published in security.txt. Encrypt sensitive reports to our PGP key.