SECURITY.md

How to report a vulnerability, what happens next, and what we commit to. The same file ships in every repository we publish.

Programme active11 researchers · 0 open reports
REPORTING
Contact: mailto:[email protected] Encryption: https://provena.eu/pgp.asc Preferred-Languages: en, nl, de Policy: https://provena.eu/security Acknowledgments: https://provena.eu/security#thanks Expires: 2027-06-30T00:00:00Z Fingerprint: 9F2A 41C8 E7B0 D3A5 64F1 9E2C 8A7D 05BB
OUR COMMITMENTS
  • Acknowledge within 24 hours, weekends included
  • Triage verdict within 5 working days
  • Fix or mitigation within 90 days, publicly if it affects verdicts
  • Credit you by name, or stay silent if you prefer
  • No legal action for good-faith research within this scope
WHAT WE ASK
  • !Use test workspaces; do not touch other customers' data
  • !No denial of service, no social engineering of staff
  • !Give us 90 days before publishing, or agree a shorter date with us
01SCOPE AND SEVERITY
IN SCOPE
  • api.provena.eu
  • app.provena.eu (panel and admin)
  • provena.eu (this site)
  • github.com/provena/*
  • Anything that could produce a wrong verdict is in scope by definition, including verifier-core logic errors.
OUT OF SCOPE
  • Missing security headers with no exploit path
  • Rate limiting on the public verifier
  • Self-XSS and clickjacking on static pages
  • Reports produced only by automated scanners
  • Watermark robustness limits we already document
CRITICAL24 hours

Forged verdict, key exposure, cross-tenant access.

HIGH7 days

Authentication bypass, ledger tampering.

MEDIUM30 days

Privilege confusion, stored XSS in the panel.

LOW90 days

Information disclosure with limited impact.

02ACKNOWLEDGEMENTS
  • APR 2026MEDIUMRole separation could be bypassed on batch signing.T. Okonkwo
  • FEB 2026HIGHTrust list cache accepted an unsigned bundle in one code path.anonymous
  • DEC 2025LOWLedger export leaked internal workspace ids.L. Bergström
  • OCT 2025MEDIUMManifest parser crashed on a malformed JUMBF box.R. Haddad

A public bug bounty with monetary rewards is planned; today the programme is private and unpaid, and we say so rather than implying otherwise.