Skip to content

Security: crestintelligence/.github

SECURITY.md

Security Policy

Crest Intelligence systems process land-title records, encumbrance certificates and court filings that contain personal data of real individuals. Security issues here are not abstract — a leak is a disclosure of someone's property and identity records.

Reporting a vulnerability

Do not open a public issue.

Email contact@crestintelligence.in with:

  • what you found and where (repo, file, endpoint)
  • how to reproduce it
  • what an attacker could reach with it

We aim to acknowledge within 3 working days and to give you a remediation timeline within 10 working days.

Please give us a reasonable window to fix the issue before disclosing it publicly. We will credit you in the fix unless you prefer otherwise.

In scope

  • Credential or API-key exposure in source, history, logs or CI
  • Unauthorised access to parcel, party or case data
  • Injection, SSRF, path traversal or deserialisation flaws in intake and report paths
  • Broken access control between tenants or investigations
  • Dependency vulnerabilities with a demonstrable path to exploitation

Out of scope

  • Findings against Government of Tamil Nadu portals or eCourts. Those are third-party systems. Report them to the relevant authority, not to us.
  • Rate-limiting or volumetric denial of service
  • Missing hardening headers with no demonstrated impact
  • Social engineering of our staff

Handling data in this org

These rules apply to everyone with commit access:

  • Never commit secrets. API keys, tokens and credentials belong in .env, which is gitignored in every repo. ANTHROPIC_API_KEY in particular must never be committed.
  • Never commit real personal data. No real names, Aadhaar or PAN numbers, phone numbers, addresses, or unredacted document scans — not in code, fixtures, test data, issues, or pull request descriptions. Use synthetic parcels for tests.
  • Never paste record extracts into an issue. Reference the case ID instead.
  • If you commit a secret by accident, treat it as disclosed: rotate the credential first, then clean the history. Rotation comes first — removing the commit does not un-leak it.

There aren't any published security advisories