Security

Reporting a vulnerability

Please do not open a public report for a security vulnerability. Report it privately instead, to security@africandsidatabank.org.

Please include:

Scope

In scope: this platform's own software and deployment configuration, and a live instance you are authorized to test (your own self-hosted node, or a staging/demo deployment explicitly opened for testing).

Out of scope: third-party services this platform integrates with but does not control (data mirroring sources, identity-verification, or email-sending services — report those to their own operators); a production instance you are not authorized to test; and denial-of-service testing against any shared/production infrastructure.

What to expect

This platform is currently built and maintained by a very small team — response times are best-effort, not covered by a formal service-level agreement. A genuine, credible report will be acknowledged and worked on; please be patient, and follow up if you haven't heard back within a couple of weeks.

Why this matters here specifically

This platform handles access-tiered and consent-gated genetic-resource data — see Governance and Terms of use for the access-and-benefit-sharing model a vulnerability could undermine. A gap that lets restricted-tier data leak, or lets an unauthorized party act as a node operator or admin, is treated as high severity.