# Security Policy

## Scope

**In scope:**
- `app.denunciasegura.cl` — complainant portal
- `api.denunciasegura.cl` — management API
- DenunciaSegura web application (dashboard, authentication, public portal)

**Out of scope:**
- Hetzner, Vercel, Resend, Upstash, or other third-party infrastructure
- Denial-of-service (DoS/DDoS) attacks
- Social engineering of ForensicCorp employees or contractors
- Physical attacks against ForensicCorp facilities

## Reporting a Vulnerability

Send your report to **security@forensic.cl** (PGP optional — see [/.well-known/pgp-key.asc](https://denunciasegura.cl/.well-known/pgp-key.asc)).

Please include:
- **Description** — clear explanation of the vulnerability
- **Steps to reproduce** — detailed steps we can follow to verify the issue
- **Estimated impact** — CVSS score / affected data / affected users
- **Proof of concept** — if available (do not exfiltrate real complainant data)

## SLA

| Milestone | Timeframe |
|-----------|-----------|
| Acknowledgment | Within 48 hours |
| Triage & severity assessment | Within 5 business days |
| Fix published (CVSS ≥ 7.0) | Within 90 days |
| Fix published (CVSS < 7.0) | Within 180 days |

We will keep you informed of progress. If you do not receive an acknowledgment within 48 hours, please follow up.

## Safe Harbor

ForensicCorp SpA will not initiate legal action against security researchers who:

1. Act in good faith and follow this disclosure policy
2. Avoid accessing, modifying, or exfiltrating real complainant data beyond what is needed for a minimal proof of concept
3. Do not intentionally disrupt service availability
4. Refrain from disclosing vulnerability details publicly before the agreed fix publication date

We consider good-faith security research a valuable contribution and will work with you to understand and resolve issues promptly.

## Hall of Fame

We'll recognize security researchers here.

## PGP Key

Our PGP public key is available at [https://denunciasegura.cl/.well-known/pgp-key.asc](https://denunciasegura.cl/.well-known/pgp-key.asc).

## Expiry Reminder

The `security.txt` file at `/.well-known/security.txt` expires on **2027-05-17**. Update it before that date.
