Skip to content

Security: araditc/sigtran.net

Security

SECURITY.md

Security Policy

SIGTRAN.NET uses private disclosure for security issues.

Reporting

Report suspected vulnerabilities to security@Sigtran.NET.

Do not publish exploit details publicly before the issue has been triaged and a coordinated fix path is available.

Response Targets

Severity Target response
Critical 2 days
High 7 days
Moderate 14 days
Low 14 days

The SDK exposes this policy through SigtranSecurityPolicy.CreateCurrentPolicy() so release tooling and downstream governance checks can reference the same response targets.

There aren't any published security advisories