Project / VERIFIED RECORD
Private security reporting is now available
OpenLegalCore now provides a monitored project-wide private channel and a canonical security-reporting policy.
RECORD FACTS
- Published
- 24 August 2026
- Verified
- 24 August 2026
- Validation
- Not applicable
PUBLIC RECORD / WHAT CHANGED
OpenLegalCore has activated a monitored project-wide channel for suspected vulnerabilities at security@openlegalcore.org. The canonical security reporting policy explains what belongs there, what to include and how a report is routed; the RFC 9116 record makes the same private contact discoverable to security tooling.
Suspected vulnerabilities should be reported privately rather than through public GitHub issues or general contribution channels. Legal OCR Pipeline also retains its component-specific GitHub Private Vulnerability Reporting path and versioned security policy.
This activation does not certify the project’s security, create a bug bounty, grant testing permission or promise a response time. The security reporting policy remains the canonical statement of scope and limitations.