Skip to content

Security: ValueaddersWorld/Value-Adders-World

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

At Value Adders World, we take security seriously. Security is a core principle — Privacy as Sacred.

How to Report

If you discover a security vulnerability, please report it responsibly:

📧 Email: security@valueadders.world

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes

What to Expect

Timeline Action
24 hours Acknowledgment of your report
48 hours Initial assessment
7 days Status update
90 days Fix deployed (or timeline communicated)

What We Ask

  • Do not publicly disclose the vulnerability until we've fixed it
  • Do not exploit the vulnerability beyond proof of concept
  • Do act in good faith to avoid privacy violations

Recognition

We recognize security researchers who help keep Value Adders World safe:

  • Credit in security advisories (if desired)
  • Listing in our Security Hall of Fame
  • Potential bounty (case-by-case)

Security Principles

1. Privacy as Sacred

All data is treated as a sacred trust:

  • AES-256-GCM encryption at rest and in transit
  • Zero-knowledge design where possible
  • Minimal data collection — only what's needed
  • User control — export and delete always available

2. PathLog Security

Our security agent protects the ecosystem:

  • Real-time threat detection
  • Compliance monitoring (SOC2, GDPR)
  • Tamper-proof audit logs
  • Vulnerability scanning

3. Code Security

  • Dependency vulnerability scanning
  • Code review requirements
  • SAST/DAST in CI/CD pipeline
  • Regular penetration testing

Supported Versions

Version Supported
Current ✅ Yes
Previous ⚠️ Security fixes only
Older ❌ No

Security Contacts


💜 Add Value. We Flourish & Prosper. 💜

There aren’t any published security advisories