This policy applies to all repositories in the CertyPro organisation unless a
repository provides its own SECURITY.md.
Please report security issues privately, never in a public issue:
- Use the Report a vulnerability button on the affected repository's Security tab to open a private advisory, or
- Email security@certy.pro.
- A clear description of the issue and its impact.
- Step-by-step instructions to reproduce it.
- Any suggested fix, if you have one.
- We will acknowledge your report as quickly as we can.
- We will keep you updated while we investigate.
- We will credit you once a fix is released, if you would like that.
Thank you for helping keep Certy and its learners safe.