Security Policy

At SBOMix, we take security seriously. This page outlines our vulnerability disclosure policy and how to report security issues responsibly.

Reporting a Vulnerability

If you discover a security vulnerability in SBOMix, please report it responsibly by contacting our security team:

Email: security@sbomix.com
GitHub: Security Advisories

Please do not:

What to Include in Your Report

To help us address the issue quickly, please include the following information:

Our Response Timeline

Security Acknowledgments

We recognize and appreciate security researchers who report vulnerabilities responsibly. Those who wish to be acknowledged will be listed on our Security Acknowledgments page.

Security Best Practices

When using SBOMix, we recommend:

Scope

This policy applies to:

This policy does not apply to:

Responsible Disclosure

We follow responsible disclosure practices and expect security researchers to do the same. This means:

Security.txt

Our security contact information is also available in our security.txt file at /.well-known/security.txt, which follows the RFC 9116 standard.

Questions?

If you have questions about this security policy, please contact security@sbomix.com.