If you discover a security vulnerability in Inqudium, please do not open a public GitHub Issue.
Instead, report it privately via email to: security@inqudium.eu
Please include:
- A description of the vulnerability
- Steps to reproduce it (if applicable)
- The potential impact as you understand it
- Any suggested fix (optional but appreciated)
We will acknowledge your report within 48 hours and aim to provide an initial assessment within 7 days. If the vulnerability is confirmed, we will work on a fix and coordinate disclosure with you before making it public.
This policy applies to the Inqudium codebase and its official modules. It does not cover third-party dependencies — please report those to the respective maintainers.
Inqudium is in early development with no production releases. Once releases are available, this document will be expanded to include supported versions and a more detailed disclosure process.