Security Policy
Please report suspected vulnerabilities privately to [email protected].
Include the affected version, reproduction steps, potential impact, and any safe proof of concept. Do not open a public issue until Ledge Top Technologies confirms that disclosure is appropriate.
Do not send:
- Real passwords, API keys, or payment credentials
- Full customer records or documents
- Raw cardholder data
- Destructive payloads against a production deployment
Reports will be acknowledged and prioritized according to severity and available information. A specific remediation or disclosure timeline cannot be guaranteed before the report is assessed.
Project Alpha is under active development. Operators are responsible for HTTPS, network controls, credential management, backups, updates, and reviewing the application for their own legal and regulatory requirements.