| Version | Supported |
|---|---|
| 3.0.x | ✅ |
| < 3.0 | ❌ |
Please report security issues privately. Do not open a public issue for a vulnerability.
- Use GitHub's Report a vulnerability (Security → Advisories) to open a private advisory, or
- open a minimal private channel with the maintainers via the repository's Security tab.
Please include reproduction steps, affected version/commit, and impact. We aim to acknowledge within 5 business days and to provide a remediation timeline after triage.
RemitMatch processes bank, customer, invoice, and remittance data. The threat model (docs/security-model.md) covers cross-tenant exposure, broken object-level authorization, malicious CSV/PDF uploads, CSV formula injection, parser resource exhaustion, replay/duplicate exports, stale/forged approvals, and log leakage of financial data.
RemitMatch is software, not a compliance certification. Operators remain responsible for TLS termination, secret management, database and object-storage encryption at rest, backups, access control to the deployment, and any regulatory obligations. See docs/operations.md.