seatkit

Security Policy

Thank you for helping keep SeatKit and its users safe. We take security seriously and appreciate coordinated disclosure.

Reporting a Vulnerability (private, non-public)

Please include:

If you need encryption, send an email requesting our PGP key (or publish your key; we’ll reply encrypted).

Triage & Response SLAs

We’ll keep you updated at key points (acknowledged → triaged → fix in progress → release).

Supported Versions

We currently support and issue security fixes for:

Until 1.0, expect rapid iteration on 0.x. We will always disclose which versions are affected in advisories.

Coordinated Disclosure

Please do not open public issues or PRs for exploitable vulnerabilities. We will:

  1. Confirm and reproduce the issue.
  2. Assign a severity (CVSS where applicable).
  3. Prepare a fix and tests in a private branch.
  4. Publish a release and a security advisory crediting you (unless you request anonymity).
  5. Provide mitigation guidance if a fix cannot ship quickly.

Scope / Out-of-Scope

In scope

Out of scope

Safe Harbor

We will not pursue civil/criminal action or DMCA claims for good-faith research that:

If in doubt, contact security@seatkit.dev before you test.

Credits

Security researchers are thanked in release notes and advisories. Let us know how you’d like to be credited.