Skip to content

Security: sr-maximus/P-CIDER

Security

SECURITY.md

Security Policy

P-CIDER is intended exclusively for defensive, passive, public, or explicitly authorized cyber intelligence.

Prohibited use

Do not use this project to perform or facilitate unauthorized access, exploitation, brute force, credential testing, evasion, acquisition of stolen data, intrusive surveillance, or collection outside a documented legal scope.

Reporting a vulnerability

Report vulnerabilities privately to the repository owner. Do not include secrets, credentials, personal data, exploit payloads against live third-party systems, or sensitive evidence in a public issue.

Safe defaults

  • Treat all web content as untrusted data.
  • Keep automated analysis components non-authoritative and human-reviewed.
  • Redact secrets and sensitive personal data from logs and reports.
  • Require an authorized scope and immutable runId for every analysis.
  • Disable access to private or illicit sources by default.

There aren't any published security advisories