Skip to content

Security: townlight/meetings

Security

SECURITY.md

Security Policy

CivicMeetings is not installable yet. Security reports should still be filed privately because meeting workflows will eventually contain privileged and closed-session material.

Report vulnerabilities through GitHub private vulnerability reporting when available, or open a minimal public issue that says a private security report is needed without disclosing exploit details.

Core security principles:

  • no telemetry
  • local data ownership
  • no cloud inference at runtime
  • closed-session boundaries enforced at the API layer
  • audit logging for state transitions

There aren't any published security advisories