Effective April 2, 2026
If you believe you have discovered a security vulnerability in any Tools for Democracy software product, please report it to:
Encrypted communication available upon request (PGP public key provided on contact).
Do not report security vulnerabilities through public GitHub issues, forums, or social media.
To help us investigate and respond efficiently, please provide:
A clear explanation of the vulnerability and its potential impact.
Which package(s) and version(s) are affected.
Detailed instructions or a proof-of-concept that demonstrates the issue.
Python version, operating system, and any relevant configuration.
| Step | Target |
|---|---|
| Acknowledgment of report | Promptly |
| Initial assessment and status update | 10 business days |
| Fix development and testing | Depends on severity |
| Coordinated disclosure | 90 days from initial report |
Remote code execution, data exfiltration. Patch within 7 days.
Privilege escalation, auth bypass. Patch within 30 days.
Information disclosure, denial of service. Patch within 60 days.
Cosmetic, informational. Next scheduled release.
We follow a 90-day coordinated disclosure timeline. We ask that reporters:
If we are unable to resolve the issue within 90 days, we will coordinate with the reporter on an appropriate disclosure timeline.
We value the security research community and commit to working with researchers in good faith.
Tools for Democracy LLC will not pursue legal action against individuals who:
This safe harbor applies to legal claims under our control (e.g., breach of contract, computer fraud). It does not bind third parties or government agencies.
This policy covers all software products published by Tools for Democracy LLC:
We appreciate security researchers who help us keep our software safe. With your permission, we will acknowledge your contribution in our release notes. We do not currently operate a paid bug bounty program.
Contact
Security reports: cory@toolsfordemocracy.us
General support: cory@toolsfordemocracy.us
Web: toolsfordemocracy.us
Responsible disclosure helps everyone. Report vulnerabilities and we'll work with you to fix them.
Report a Vulnerability