Skip to content

Security: learn-rudi/rudi

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in RUDI, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Contact the maintainers directly
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will respond within 48 hours and work with you to address the issue.

Security Considerations

Website Security

  • All forms use proper input validation
  • HTTPS enforced on all pages
  • No sensitive data stored client-side
  • Regular dependency updates

User Data

  • Survey responses are anonymous
  • No personally identifiable information collected without consent
  • Data stored securely in Google Sheets with access controls
  • No third-party tracking beyond basic analytics

Best Practices

  • Keep browser and devices updated
  • Use strong passwords for any accounts
  • Report suspicious activity

Responsible Disclosure

We appreciate security researchers who responsibly disclose vulnerabilities:

  1. Report directly to maintainers (not public issues)
  2. Allow reasonable time for fixes (30 days minimum)
  3. Don't publicly disclose until resolved
  4. Provide clear reproduction steps

Contact

For security concerns, contact the RUDI team through the website contact form or email.

There aren’t any published security advisories