SIGTRAN.NET uses private disclosure for security issues.
Report suspected vulnerabilities to security@Sigtran.NET.
Do not publish exploit details publicly before the issue has been triaged and a coordinated fix path is available.
| Severity | Target response |
|---|---|
| Critical | 2 days |
| High | 7 days |
| Moderate | 14 days |
| Low | 14 days |
The SDK exposes this policy through SigtranSecurityPolicy.CreateCurrentPolicy() so release tooling and downstream governance checks can reference the same response targets.