business-registry

Security policy

Supported versions

Security fixes are applied to main and, when practical, to the latest tagged registry snapshot. Historical commits and older snapshots are immutable publication records and are not maintained releases.

Report a vulnerability privately

Do not open a public issue for a suspected vulnerability, exposed secret, private-data disclosure, or publication-control bypass.

Use GitHub’s private vulnerability reporting for this repository when the Report a vulnerability button is available on the Security page. If it is not available, email hello@vizai.io with the subject SECURITY: business-registry.

Include only what is necessary to reproduce and assess the issue:

Do not include live credentials, unrelated personal data, or destructive test results. If sensitive material is already public, provide its location rather than duplicating it.

In scope

Public factual corrections, business disputes, removal requests, and ordinary data-quality concerns are not security vulnerabilities. Use Correction, dispute, and removal.

Response targets

These are operational targets, not guarantees:

VizAI asks reporters to avoid privacy violations, service disruption, social engineering, and data destruction. Good-faith research that follows this policy will be handled through coordinated disclosure.