Skip to content

Security: realarpan/cloudvault-pro

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities. Currently supported versions:

Version Supported
2.1.x
2.0.x
< 2.0

Reporting a Vulnerability

We take the security of CloudVault Pro seriously. If you believe you have found a security vulnerability, please report it to us as described below.

Please Do NOT:

  • Open a public GitHub issue
  • Discuss the vulnerability in public forums
  • Exploit the vulnerability beyond what is necessary to demonstrate it

Please DO:

  1. Email us directly at: security@cloudvault-pro.com (or create a private security advisory on GitHub)
  2. Include details such as:
    • Description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact
    • Suggested fix (if you have one)
  3. Allow time for us to respond (typically within 48 hours)
  4. Work with us to understand and resolve the issue

What to Expect

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
  • Updates: We will keep you informed about our progress
  • Fix Timeline: We aim to release security fixes within 7-14 days for critical issues
  • Credit: We will credit you in our release notes (unless you prefer to remain anonymous)

Security Best Practices for Users

  • Keep your CloudVault Pro installation up to date
  • Use strong, unique passwords
  • Enable two-factor authentication when available
  • Regularly review access logs
  • Keep your dependencies updated
  • Use HTTPS in production

Disclosure Policy

When we receive a security bug report, we will:

  1. Confirm the problem and determine affected versions
  2. Audit code to find similar problems
  3. Prepare fixes for all supported versions
  4. Release new security fix versions as soon as possible

Thank you for helping keep CloudVault Pro and our users safe!

There aren’t any published security advisories