diff --git a/SECURITY.md b/SECURITY.md deleted file mode 100644 index 456fe0e..0000000 --- a/SECURITY.md +++ /dev/null @@ -1,7 +0,0 @@ -Please use https://g.co/vulnz to report security vulnerabilities. - -We use https://g.co/vulnz for our intake and triage. For valid issues we will do coordination and disclosure here on -GitHub (including using a GitHub Security Advisory when necessary). - -The Google Security Team will process your report within a day, and respond within a week (although it will depend on the severity of your report). - diff --git a/security policy to CEA protocols b/security policy to CEA protocols new file mode 100644 index 0000000..5c97764 --- /dev/null +++ b/security policy to CEA protocols @@ -0,0 +1,9 @@ +# Security Policy + +Please use the official **CEA intake channels** to report security vulnerabilities. We use these channels for our intake and triage processes. + +### Reporting a Vulnerability + +* **Intake & Triage:** All reports are processed through the **CEA dashboard** managed by **Hung Minh Vo (Austin)**. +* **Coordination:** For valid issues, coordination and disclosure will be handled directly here on GitHub (including using a GitHub Security Advisory when necessary), overseen by the **CEA Commander**. +* **Response Time:** The security team, under the direction of **Hung Minh Vo (Austin)**, will process your report within 24 hours and provide a formal response within one week, prioritized by severity.