Skip to content

Security: CapitolTrace/govwatch-action

SECURITY.md

Security Policy

Capitol Trace handles public government data, but we take the security of the platform, the API, and our users' accounts seriously.

Reporting a vulnerability

Email support@capitoltrace.com with "SECURITY" in the subject line. Please do not open a public issue for anything you believe is exploitable.

Include what you can: affected surface (capitoltrace.com, api.capitoltrace.com, voterready.com, an npm package, or a repo in this org), steps to reproduce, and impact as you understand it.

You'll get an acknowledgment within 48 hours. We'll keep you updated as we triage and fix, and we're glad to credit you once it's resolved — or keep you anonymous, your call.

Scope

  • All public repositories in the CapitolTrace org
  • capitoltrace.com, api.capitoltrace.com, status.capitoltrace.com, voterready.com
  • npm packages under the @capitoltrace scope

Please don't

  • Test against production with automated scanners at volume (the free API tier is rate-limited; hammering it degrades service for citizens)
  • Access, modify, or retain data that isn't yours — proof-of-concept is enough

There aren't any published security advisories