diff --git a/SECURITY.md b/SECURITY.md index 7859ca745..b12f96cfd 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,7 +1,9 @@ -Security issues and bugs should be reported privately, via email. To report a security issue, please send an email to **security@btcpayserver.org** (not for support). +# How to handle security issues and bug reports? -You will receive a reply indicating the next steps in handling your report. If for some reason you do not receive a reply within 24 hours, please follow up via email to ensure the original message was received. +Security issues and bugs should be reported privately via email. To report a security issue, please email **security@btcpayserver.org** (not for support). + +You will receive a reply indicating the next steps in handling your report. If, for some reason, you do not receive a response within 24 hours, please follow up via email to ensure the original message was received. After the initial reply to your report, you will be informed of the progress towards a fix and full announcement. You may be asked to provide additional information or guidance. -We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions. +We appreciate your efforts to disclose your findings responsibly and will make every effort to acknowledge your contributions.