diff --git a/static/index.html b/static/index.html index bbc0b6900..c114ba8f0 100644 --- a/static/index.html +++ b/static/index.html @@ -4266,6 +4266,10 @@ Donate +
+ + Security +
Privacy Policy diff --git a/static/security-policy.html b/static/security-policy.html new file mode 100644 index 000000000..b46c37130 --- /dev/null +++ b/static/security-policy.html @@ -0,0 +1,136 @@ + + + + + + Monkeytype + + + + + + + + + + + + + + + + + + + + + + + + + + +
+
+ +
+
+

+ Monkeytype takes the security of its platform seriously. If you are a + security researcher and have found a vulnerability, we would like to + work with you to remediate the issue. +

+

Table of Contents

+ + + +

How to Disclose a Vulnerability?

+

+ For vulnerabilities that impact the confidentiality, integrity and + availability of monkeytype services, please send your disclosure via + (1) + mail + , or (2) private discord chat to + miodec + . For non-security related platform bugs, follow the bug submission + + guidelines + + .Include as much detail as possible to ensure reproducibility. At a + minimum, vulnerability disclosures should include: +

+
    +
  • Vulnerability Description
  • +
  • Proof of Concept
  • +
  • Impact
  • +
  • Screenshots or Proof
  • +
+ +

Submission Guidelines

+

+ Do not engage in activities that might cause a denial of service + condition or create significant strains on critical resources. Do not + engage in activities that negatively impact users of the site outside + of test or dummy accounts. +

+
+
+ + +