Capitol Trace handles public government data, but we take the security of the platform, the API, and our users' accounts seriously.
Email support@capitoltrace.com with "SECURITY" in the subject line. Please do not open a public issue for anything you believe is exploitable.
Include what you can: affected surface (capitoltrace.com, api.capitoltrace.com, voterready.com, an npm package, or a repo in this org), steps to reproduce, and impact as you understand it.
You'll get an acknowledgment within 48 hours. We'll keep you updated as we triage and fix, and we're glad to credit you once it's resolved — or keep you anonymous, your call.
- All public repositories in the
CapitolTraceorg capitoltrace.com,api.capitoltrace.com,status.capitoltrace.com,voterready.com- npm packages under the
@capitoltracescope
- Test against production with automated scanners at volume (the free API tier is rate-limited; hammering it degrades service for citizens)
- Access, modify, or retain data that isn't yours — proof-of-concept is enough