Housewatch Digital software may interact with operational, personnel, dispatch, or department-controlled information. We take reports that could affect the confidentiality, integrity, or availability of those systems seriously.
Security fixes are normally applied to the latest supported release of each project. A repository's README or release notes may document additional supported versions. If support status is unclear, report the issue so it can be assessed.
Do not disclose a suspected vulnerability in a public issue, discussion, pull request, or social post.
Use the affected repository's Security tab and select Report a vulnerability when private vulnerability reporting is available. If it is not available, use the contact method listed on the Housewatch Digital organization profile and ask for a private security-reporting channel. Do not include vulnerability details in that initial public request.
Please include, when possible:
- the affected repository, version, or commit;
- the deployment or configuration involved;
- a description of the impact and affected data or systems;
- minimal, safe reproduction steps or a proof of concept;
- known mitigations or workarounds; and
- a secure way to contact you.
Never use live patient data, active incident data, real credentials, or a production department system to demonstrate a vulnerability without explicit authorization.
We will make a reasonable effort to acknowledge the report, assess its impact, and keep the reporter informed as remediation progresses. Please allow time for a fix and coordinated disclosure before publishing details.
Reports made in good faith to improve the safety of Housewatch Digital projects are welcome. This policy does not authorize testing against systems, accounts, data, or infrastructure you do not own or have explicit permission to test.