Seenly

🚨 Seenly Social — Security Policy & Guidelines


Security is foundational to the Seenly ecosystem. We welcome responsible disclosure from security researchers and the open-source community.
---

1. Supported Versions


| Version | Supported | | :--- | :--- | | v1.0.x (Current) | ✅ Supported | | < v1.0 | ❌ End of Life |
---

2. Reporting a Vulnerability


If you discover a security vulnerability within Seenly Social, please follow these steps:
1. Do not create a public GitHub issue. 2. Send a detailed report to our security team at: security@seenly.social (or via GitHub Private Vulnerability Reporting). 3. Include: - Description of the vulnerability. - Proof of Concept (PoC) or reproduction steps. - Potential impact assessment. 4. We acknowledge all reports within 24 hours and will provide regular status updates until resolution.
---

3. Security Hardening Measures


- Content Security Policy (CSP): Strict resource limits preventing unauthorized script injection. - Cross-Site Scripting (XSS): Strict React DOM sanitization and no `eval()` execution. - Cross-Origin Resource Sharing (CORS): Restricted to authorized Seenly domains. - Rate Limiting: Applied to all authentication, upload, and API endpoints. - HTTPS & TLS: Enforced across all web and WebSocket communication channels.