Security Policy — EOLkits

Supported Version

Only the current default-branch revision and most recent release are supported.

Report a Vulnerability

Do not file a public issue containing exploit details, credentials, customer data, or a private report URL.

Use GitHub private vulnerability reporting:

  1. Open https://github.com/ntoledo319/EOLkits/security/advisories.
  2. Select Report a vulnerability.
  3. Include the affected revision, impact, reproduction, and any suggested fix.

If private reporting is unavailable, email hello@toledotechnologies.com with the subject EOLkits security report. There is no guaranteed response time.

Current Boundaries

Research Rules

Good-faith research must avoid data destruction, privacy violations, persistence, denial of service, social engineering, and access to other users' data. Stop and report if you encounter customer data or a secret. Third-party systems such as Stripe, GitHub, Resend, and the hosting provider are outside EOLkits authorization.

There is no cash or credit bug-bounty program. Coordinated disclosure and clear credit are welcome when requested by the reporter.

User Checklist