Skip to content

Security: DevFoundry-labs/remitmatch

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
3.0.x
< 3.0

Reporting a vulnerability

Please report security issues privately. Do not open a public issue for a vulnerability.

  • Use GitHub's Report a vulnerability (Security → Advisories) to open a private advisory, or
  • open a minimal private channel with the maintainers via the repository's Security tab.

Please include reproduction steps, affected version/commit, and impact. We aim to acknowledge within 5 business days and to provide a remediation timeline after triage.

What we treat as sensitive

RemitMatch processes bank, customer, invoice, and remittance data. The threat model (docs/security-model.md) covers cross-tenant exposure, broken object-level authorization, malicious CSV/PDF uploads, CSV formula injection, parser resource exhaustion, replay/duplicate exports, stale/forged approvals, and log leakage of financial data.

Operator responsibilities

RemitMatch is software, not a compliance certification. Operators remain responsible for TLS termination, secret management, database and object-storage encryption at rest, backups, access control to the deployment, and any regulatory obligations. See docs/operations.md.

There aren't any published security advisories