> For the complete documentation index, see [llms.txt](https://delpho.gitbook.io/delpho-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://delpho.gitbook.io/delpho-docs/audits-and-security/security-contact-and-disclosure-policy.md).

# Security contact and disclosure policy

This page is how to report a security issue to Delpho, what to expect in response, and the disclosure norms the team commits to.

## Security contact

| Channel       | Address    |
| ------------- | ---------- |
| Primary email | \[PENDING] |

## Response SLA

| Severity     | Acknowledgment  | Triage          | Public disclosure                            |
| ------------ | --------------- | --------------- | -------------------------------------------- |
| Critical     | Within hours    | Within 24 hours | After remediation, coordinated with reporter |
| High         | Within 24 hours | Within 72 hours | After remediation, coordinated with reporter |
| Medium / Low | Within 72 hours | Within 1 week   | After remediation, coordinated with reporter |

## Disclosure norms

Delpho follows coordinated responsible disclosure:

* **Reporters do not publicly disclose findings before remediation is complete.** Delpho will work with the reporter to set a remediation timeline appropriate to the severity.
* **Delpho does not retaliate against good-faith security research.** Researchers acting in good faith and within the bounds described here are not subject to legal action for testing or reporting.
* **Acknowledgment.** Reporters of valid findings are credited, where permitted, in disclosure announcements once remediation is complete.

## Related pages

* [Audit register](/delpho-docs/audits-and-security/audit-register.md), for the security baseline.
