Skip to content

Security: icecompany-tech/.github

Security

SECURITY.md

Security Policy

Icecompany builds infrastructure for the private internet. We take vulnerability reports seriously.

Reporting a vulnerability

Email security@icecompany.tech. Do not open a public GitHub issue for security reports.

Include:

  • the affected product (Iceslab, Iceshard, Icepath, Icecore, Iceproxy)
  • the version or commit hash
  • a clear description of the issue
  • reproduction steps or a proof of concept
  • the impact you observed

What to expect

We are a small team. We aim to:

  • Acknowledge your report within a few days.
  • Give an initial assessment once we have reproduced or understood the issue.
  • Keep you updated until it is resolved or closed.

We do not currently run a paid bug bounty program. Reporters are credited in release notes by default. If you prefer to stay anonymous, tell us.

Scope

In scope:

  • code in repositories under github.com/icecompany-tech
  • production services on icecompany.tech and its subdomains

Out of scope:

  • third-party services we depend on (report to them directly)
  • denial-of-service tests against production infrastructure
  • social engineering of staff or users
  • physical attacks

Encrypted reports

A PGP key is available on request. Email security@icecompany.tech and we will send it.

There aren't any published security advisories