Security
Report a security issue privately.
If you find a vulnerability in Odal Node, email security@odal-node.io. Please do not open a public issue. Include what you found and what it could affect, how to reproduce it, the version you tested, and any fix you would suggest.
We follow coordinated disclosure: we fix first, then publish, together with you.
What happens next
How we respond.
- Within 48 hoursWe acknowledge your report.
- Within 5 business daysWe assess it and classify its severity.
- Within 14 daysA fix or mitigation for critical and high-severity issues.
- Within 30 daysA fix or mitigation for medium and low-severity issues.
- After the fixPublic disclosure, coordinated with you.
Protections
How passports and keys are protected.
Your key stays with you
Every passport is signed on your own servers, with a key that is encrypted at rest and never leaves them.
Anyone can check a passport
Signatures are checked against the identity on your own web domain, so verifying a passport never depends on us.
Rules run in a sandbox
A product group's checks run isolated from the network, the files and the signing key, and a node refuses checks that are not signed by a key its operator trusts, unless the operator deliberately switches that check off for development.
Safe by default
A node will not start with the sample admin login or key-store passphrase, or with an empty passphrase, and it reports which of the services it relies on are real and which are stand-ins.
Releases that list their contents
Each release's container images carry a list of the components inside them and a record of how they were built. The images are not public yet.
Dependencies watched
Every change is checked against known security advisories, and any advisory we accept is recorded with its reasoning and an expiry date.
More detail
Where to read further.
The full policy is in the security policy, and how a node protects keys, data and access is in the documentation. What we can and cannot see of your data is on What Odal can see.