Engineering Gap
No SECURITY.md or vulnerability reporting channel exists for a platform handling humanitarian aid and recipient PII. Security researchers have no documented process for responsible disclosure.
Codebase Evidence
- No SECURITY.md at repo root or in docs/
- README.md mentions no security contact
- .github/ has no security policy
Risk Profile
Current Risk
Vulnerabilities may be publicly disclosed before patching or go unreported entirely.
Business Impact
Uncontrolled vulnerability disclosure. Potential exploit window. Reputational damage.
Remediation Strategy
Create SECURITY.md at repo root with: supported versions, reporting process (email/PGP), response timeline (48h ack, 7-30d patch), coordinated disclosure policy.
Success Conditions
Change Surface
New file: SECURITY.md
Security Review
Enables responsible disclosure — net positive security impact.
Completion Checklist
Engineering Gap
No SECURITY.md or vulnerability reporting channel exists for a platform handling humanitarian aid and recipient PII. Security researchers have no documented process for responsible disclosure.
Codebase Evidence
Risk Profile
Current Risk
Vulnerabilities may be publicly disclosed before patching or go unreported entirely.
Business Impact
Uncontrolled vulnerability disclosure. Potential exploit window. Reputational damage.
Remediation Strategy
Create SECURITY.md at repo root with: supported versions, reporting process (email/PGP), response timeline (48h ack, 7-30d patch), coordinated disclosure policy.
Success Conditions
Change Surface
New file: SECURITY.md
Security Review
Enables responsible disclosure — net positive security impact.
Completion Checklist