Skip to content

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Security Policy

SKOPAQ AI PRIVATE LIMITED takes security reports seriously, for its products, its public repositories and its website alike. Thank you for taking the time to tell us about a problem rather than exploiting it.

Reporting a vulnerability

Do not open a public issue, discussion or pull request for a security problem. A public report tells attackers before it tells us.

Report privately, by either route:

  1. Email — preferred. solutions@skopaq.com, with [SECURITY] at the start of the subject line.
  2. GitHub private vulnerability reporting. The repository's Security tab → Report a vulnerability, where it is enabled.

Please give us a reasonable window to fix the problem before publishing.

If you found a credential or key that appears to belong to SKOPAQ AI — in a repository, its git history, a built artefact or a deployed bundle — treat it as urgent and say so in the subject line.

What to include

The more of this we get, the faster the fix:

  • The repository, URL or product, and which part of it.
  • Environment: browser and version, operating system, runtime, and viewport if it is layout-dependent.
  • Step-by-step reproduction, starting from a clean state.
  • A proof of concept — a request, a payload, a short recording.
  • The impact you believe it has, and any prerequisites (a specific browser, an authenticated third-party service, a particular configuration).
  • Whether you have shared this with anyone else, and any disclosure deadline you intend to hold us to.

What to expect

We acknowledge every report. If we conclude a report is not a vulnerability, we explain why rather than close it silently. We tell you when the fix is live, and we are glad to credit you by name or handle if you would like that.

We do not currently run a paid bug bounty. Reports are still welcome, and credit is offered gladly.

Supported versions

Fixes land on the default branch of the repository concerned, and the website is continuously deployed from its main branch. Older commits, tags, forks and mirrors are not supported — update to the current default branch.

Scope

In scope

  • The website as deployed at skopaq.com and at skopaq.ai. Both hostnames serve the same application; skopaq.com is the canonical one.
  • The public repositories in this organisation, and anything their built artefacts expose — leaked secrets, injectable markup, unsafe handling of input, dependency vulnerabilities with a demonstrated path to exploitation.
  • Supply-chain issues in a committed dependency tree.
  • Anything else SKOPAQ AI operates.

Out of scope

  • Findings from an automated scanner with no working proof of concept, and "outdated dependency" reports with no exploitable path in the code concerned.
  • Missing security headers, TLS configuration, or DNS/CDN settings on infrastructure we do not control — report those to the relevant provider, though we are happy to hear about them.
  • Volumetric denial of service, load testing, and spamming the contact form.
  • Self-XSS, and issues requiring a physically compromised device, a malicious browser extension, or an already root-compromised OS.
  • Clickjacking or missing anti-CSRF on pages with no authentication and no state-changing action.
  • Social engineering of SKOPAQ AI staff or clients.
  • Vulnerabilities in the upstream of a repository we have forked. Report those to the upstream project; report anything specific to our fork to us.
  • The separate Skopaq: Your AI QA Engineering Team product, which is not built from any repository here and is no longer served at skopaq.ai. Reports about it are welcome at the same address, but they are not in scope for this policy.

Safe harbour

We will not pursue or support legal action against anyone who, in good faith:

  • reports promptly and privately through the channels above,
  • limits testing to what is necessary to demonstrate the issue,
  • does not access, modify, exfiltrate or destroy data belonging to SKOPAQ AI, its clients or its users,
  • does not degrade the service for others, and
  • gives us reasonable time to fix the issue before disclosing it publicly.

About

Organization profile and shared community health files

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors