Security Policy

This policy defines the security principles of termissh and the process for reporting vulnerabilities.

Last updated: February 27, 2026

1. Scope

  • termissh web app, API endpoints, and self-host runtime are in scope.
  • Third-party integrations are governed by their own security policies.

2. Core controls

  • AES-256 encryption protects sensitive fields.
  • Authentication, role-based access, and API key controls are enforced together.
  • Critical actions are tracked with audit logs.

3. Vulnerability disclosure

  • Report security issues to [email protected] under responsible disclosure.
  • Reports are triaged within 72 hours.
  • Validated findings receive a remediation and disclosure timeline.

4. Safe harbor

  • Good-faith testing that avoids data integrity impact is treated as authorized research.
  • Tests causing user harm, data exfiltration, or service disruption are out of scope.

5. Out of scope

  • Social engineering and physical intrusion attempts.
  • Unverified automated scanner output.
  • Findings that cannot be reproduced outside non-production environments.