Security Policy
This policy defines the security principles of termissh and the process for reporting vulnerabilities.
Last updated: February 27, 2026
1. Scope
- termissh web app, API endpoints, and self-host runtime are in scope.
- Third-party integrations are governed by their own security policies.
2. Core controls
- AES-256 encryption protects sensitive fields.
- Authentication, role-based access, and API key controls are enforced together.
- Critical actions are tracked with audit logs.
3. Vulnerability disclosure
- Report security issues to [email protected] under responsible disclosure.
- Reports are triaged within 72 hours.
- Validated findings receive a remediation and disclosure timeline.
4. Safe harbor
- Good-faith testing that avoids data integrity impact is treated as authorized research.
- Tests causing user harm, data exfiltration, or service disruption are out of scope.
5. Out of scope
- Social engineering and physical intrusion attempts.
- Unverified automated scanner output.
- Findings that cannot be reproduced outside non-production environments.