Skip to content
NDTdigital.
PTEN

Last editorial review:

Security policy.

How to report vulnerabilities affecting NDT digital projects and services.

Responsible private reporting helps NDT digital investigate and address security risks.

This is a translation provided for convenience. The Portuguese version is the binding one, and it prevails in case of any divergence.

Report a vulnerability privately

Send security reports to security@ndtdigital.com.br or use GitHub Private Vulnerability Reporting when it is enabled for the affected repository.

Do not publish vulnerability details in issues, discussions, pull requests, or social media.

What to include

Include the affected project or service, version when known, a clear description, reproduction steps, observed impact, and relevant evidence. Do not include credentials or unrelated personal data.

Scope and supported versions

This policy covers software, repositories, services, APIs, websites, and infrastructure maintained by NDT digital. Project-specific security policies take precedence.

Actively maintained projects and supported versions receive priority for security fixes.

Response and responsible disclosure

NDT digital may validate the report, assess impact, prepare mitigation, and coordinate disclosure. Timing depends on severity, complexity, and operational risk.

Give NDT digital a reasonable opportunity to investigate before publishing sensitive details, and limit testing to what is necessary to demonstrate the issue safely.

Third-party components

NDT digital products may depend on third-party software, libraries, or infrastructure. When the flaw sits only in an external component, remediation may involve updating dependencies, changing configuration, or coordinating with the upstream project. Reports about an NDT product's exposure remain relevant.

Newsletter

Get what NDT publishes

An occasional email with project notes, technical decisions, and what actually worked. No daily blasts.

How NDT handles data is in the Privacy policy.