Skip to content

Security: ANYTECHS/clips-backend

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability within ClipCash, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please send an email to security@clipcash.io with the following details:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any mitigation suggestions

We will acknowledge your report within 48 hours and work with you to resolve the issue promptly.

Supported Versions

We actively maintain the latest release and the previous major version. Security patches are applied to supported versions.

Security Best Practices

  • Use strong, unique passwords for all accounts
  • Enable MFA for sensitive operations
  • Keep your API tokens secure and rotate them regularly
  • Review access logs periodically

Disclosure Policy

We follow a coordinated disclosure process. Once a fix is deployed, we will publish a security advisory and credit the reporter (unless they wish to remain anonymous).

There aren't any published security advisories