From 35d9d374c9af5ac0b07338bfd1c0dc67a8c0f3b3 Mon Sep 17 00:00:00 2001
From: Dante Sanchez
Date: Tue, 22 Sep 2026 13:33:31 -0400
Subject: [PATCH] add security contact info
---
.github/SECURITY.md | 14 ++++++++++
.well-known/security.txt | 5 ++++
README.md | 6 +++++
_config.yml | 2 ++
_includes/sections/footer.html | 2 ++
security.html | 47 ++++++++++++++++++++++++++++++++++
6 files changed, 76 insertions(+)
create mode 100644 .github/SECURITY.md
create mode 100644 .well-known/security.txt
create mode 100644 security.html
diff --git a/.github/SECURITY.md b/.github/SECURITY.md
new file mode 100644
index 00000000..fdbb9baf
--- /dev/null
+++ b/.github/SECURITY.md
@@ -0,0 +1,14 @@
+# Security Policy
+
+If you believe you've found a security vulnerability affecting the hypha.coop website or our work, please email **security@hypha.coop** rather than opening a public issue.
+
+Please include:
+
+- A description of the issue and its potential impact.
+- Steps to reproduce it, or a proof of concept.
+- The affected URL, repository, or system.
+- How we can reach you if we have questions.
+
+We ask that you keep the details private until we've had a chance to fix the issue, and that you avoid accessing or changing data that isn't yours, disrupting our services, or social engineering our team or partners.
+
+More information: https://hypha.coop/security/
diff --git a/.well-known/security.txt b/.well-known/security.txt
new file mode 100644
index 00000000..a39e75ed
--- /dev/null
+++ b/.well-known/security.txt
@@ -0,0 +1,5 @@
+Contact: mailto:security@hypha.coop
+Expires: 2027-09-01T00:00:00.000Z
+Preferred-Languages: en
+Canonical: https://hypha.coop/.well-known/security.txt
+Policy: https://hypha.coop/security/
diff --git a/README.md b/README.md
index 8bd5a115..0790e55e 100644
--- a/README.md
+++ b/README.md
@@ -35,6 +35,12 @@ We also auto-deploy `staging` branch to [staging.hypha.coop](https://staging.hyp
Staging uses Let's Encrypt staging enviroment to allow for higher limits than their production environment. This allow us to redeploy sites on staging without hitting the limit of Let's Encrypt production. As a result when accessing staging you will be prompted about invalid certificate on your browser. More information on Let's Encrypt staging enviroment [here.](https://letsencrypt.org/docs/staging-environment/)
+## 🔒 Security
+
+To report a security vulnerability, email [security@hypha.coop](mailto:security@hypha.coop). See [`.github/SECURITY.md`](./.github/SECURITY.md) and the [security page](https://hypha.coop/security/).
+
+[`.well-known/security.txt`](./.well-known/security.txt) has an `Expires` date that must be renewed at least once a year (RFC 9116 allows at most one year ahead).
+
## 📑 Attribution
- `favicon.ico`: [Rorschach Test](https://thenounproject.com/nicky.humphreys/collection/repeat-pattern/?i=871159) by Nicky Knicky from the Noun Project
diff --git a/_config.yml b/_config.yml
index 415b539b..e72abfae 100644
--- a/_config.yml
+++ b/_config.yml
@@ -1,6 +1,8 @@
title: Hypha
email: hello@hypha.coop
email-hidden: "%68%65%6c%6c%6f%40%68%79%70%68%61%2e%63%6f%6f%70"
+security_email: security@hypha.coop
+security_email-hidden: "%73%65%63%75%72%69%74%79%40%68%79%70%68%61%2e%63%6f%6f%70"
phone: +1 437-887-6936
address: Toronto, ON
github: https://github.com/hyphacoop
diff --git a/_includes/sections/footer.html b/_includes/sections/footer.html
index 937835b7..0efac196 100644
--- a/_includes/sections/footer.html
+++ b/_includes/sections/footer.html
@@ -44,6 +44,8 @@ Policies and Licensing Information
href="https://handbook.hypha.coop/Policies/data.html" target="_blank" class="accent link"
rel="noopener">How We Use Data and Working Open.
+ Found a security issue? Please report it
+ to {{ site.security_email }}.
This site is published using Distributed Press.
diff --git a/security.html b/security.html
new file mode 100644
index 00000000..406c2e85
--- /dev/null
+++ b/security.html
@@ -0,0 +1,47 @@
+---
+layout: default
+title: Security
+excerpt: "If you believe you've found a security vulnerability affecting our website or our work, please email security@hypha.coop."
+---
+
+
+
+
+
+ {{ page.title }}
+
+
+ If you believe you've found a security vulnerability affecting this website or our work, please let us know by emailing
+ {{ site.security_email }}.
+
+
+
+
+
+
+
What to include
+
+ - A description of the issue and its potential impact.
+ - Steps to reproduce it, or a proof of concept.
+ - The affected URL, repository, or system.
+ - How we can reach you if we have questions.
+
+
+
What to expect
+
+ We'll read every report and get back to you. We ask that you keep the details private until we've had a chance to fix the issue.
+
+
+
Acting in good faith
+
+ Please avoid accessing or changing data that isn't yours, disrupting our services or the people who use them, and social engineering our team or partners.
+
+
+
Our open source work
+
+ Much of our work is open source and lives on GitHub.
+ Please use the same email address to report vulnerabilities in any of it, rather than opening a public issue.
+ For how we handle data more generally, see How We Use Data in our handbook.
+
+
+