Skip to content

Security: Hack23/cia

SECURITY.md

Hack23 Logo

๐Ÿ” Security Policy โ€” Citizen Intelligence Agency

๐Ÿ›ก๏ธ Security Through Transparency and Vulnerability Management
๐ŸŽฏ Enterprise-grade Security Posture and Incident Response

Owner Version Effective Date Review Cycle

๐Ÿ“‹ Document Owner: CEO | ๐Ÿ“„ Version: 1.0 | ๐Ÿ“… Last Updated: 2026-02-20 (UTC)
๐Ÿ”„ Review Cycle: Quarterly | โฐ Next Review: 2026-05-20


๐ŸŽฏ Purpose Statement

This security policy establishes vulnerability disclosure and incident response procedures for the Citizen Intelligence Agency platform, implementing Vulnerability Management and Incident Response Plan from Hack23 AB's ISMS framework.

Our security approach demonstrates our commitment to transparency and operational excellence, ensuring that vulnerabilities are managed systematically with documented response times and coordinated disclosure processes.

โ€” James Pether Sรถrling, CEO/Founder


Supported Versions

This project is under active development, and we provide security updates for the latest version only. Please ensure you're using the latest version of the project to receive security updates.

Version Supported ISMS Policy
latest โœ… Vulnerability Management

Security Posture

The Citizen Intelligence Agency maintains strong security practices:

  • โœ… SLSA Level 3 - Supply chain security with build attestation
  • โœ… Automated Security Scanning - SAST (CodeQL), SCA (OWASP Dependency Check), DAST (ZAP)
  • โœ… OpenSSF Scorecard - Continuous security posture assessment
  • โœ… Comprehensive Testing - Unit, integration, and E2E security tests

Evidence:


Reporting a Vulnerability

We take the security of the Citizen Intelligence Agency project seriously. If you have found a potential security vulnerability, we kindly ask you to report it privately, so that we can assess and address the issue before it becomes publicly known.

What Constitutes a Vulnerability

A vulnerability is a weakness or flaw in the project that can be exploited to compromise the security, integrity, or availability of the system or its data. Examples of vulnerabilities include, but are not limited to:

  • Unauthenticated access to sensitive data
  • Injection attacks (e.g., SQL injection, cross-site scripting)
  • Insecure defaults or configurations
  • Insufficient access controls
  • Remote code execution

How to Privately Report a Vulnerability using GitHub

Please follow these steps to privately report a security vulnerability:

  1. On GitHub.com, navigate to the main page of the cia repository.
  2. Under the repository name, click Security. If you cannot see the "Security" tab, select the dropdown menu, and then click Security.
  3. In the left sidebar, under "Reporting", click Advisories.
  4. Click Report a vulnerability to open the advisory form.
  5. Fill in the advisory details form. Provide as much information as possible to help us understand and reproduce the issue.
  6. At the bottom of the form, click Submit report.

After you submit the report, the maintainers of the Citizen Intelligence Agency repository will be notified. They will review the report, validate the vulnerability, and take necessary actions to address the issue. You will be added as a collaborator and credited for the security advisory.

Disclosure Timeline

Upon receipt of a vulnerability report, our team will:

  1. Acknowledge the report within 48 hours
  2. Validate the vulnerability within 7 days
  3. Develop and release a patch or mitigation within 30 days, depending on the complexity and severity of the issue
  4. Publish a security advisory with a detailed description of the vulnerability and the fix

Recognition and Anonymity

We appreciate your effort in helping us maintain a secure and reliable project. If your report results in a confirmed security fix, we will recognize your contribution in the release notes and/or a public acknowledgment, unless you request to remain anonymous.

Thank you for helping us keep the Citizen Intelligence Agency project and its users safe.


๐Ÿ” ISMS Framework Integration

The Citizen Intelligence Agency security practices are part of Hack23 AB's comprehensive Information Security Management System (ISMS):

๐Ÿ“‹ Related ISMS Policies

๐Ÿ›ก๏ธ Policy ๐Ÿ“Š Application to CIA Platform
Vulnerability Management 48h response SLA, coordinated disclosure process
Incident Response Plan P1-P4 incident classification, escalation procedures
Secure Development Policy Security testing requirements, code review standards
Information Security Policy Overall security governance framework

๐Ÿ” Comprehensive Security Documentation

For complete details on how CIA implements security controls:


๐Ÿ“š Related Documents

๐Ÿ” Security Policies & Procedures

๐Ÿ—๏ธ CIA Security Documentation

๐Ÿ”„ Development & Operations

๐Ÿค Third-Party & Transparency


๐Ÿ“‹ Document Control:
โœ… Approved by: James Pether Sรถrling, CEO
๐Ÿ“ค Distribution: Public
๐Ÿท๏ธ Classification: Confidentiality: Public Integrity: Moderate Availability: Standard
๐Ÿ“… Effective Date: 2026-02-20
โฐ Next Review: 2026-05-20
๐ŸŽฏ Framework Compliance: ISO 27001 NIST CSF 2.0 CIS Controls AWS Well-Architected

There arenโ€™t any published security advisories