Language: English | Português (Brasil)
Security is treated as part of the engineering lifecycle at NDT digital.
We appreciate responsible reports of potential security vulnerabilities affecting NDT digital repositories, applications, services, APIs, infrastructure, or other publicly accessible technology.
Please report suspected security vulnerabilities privately.
Preferred reporting channels:
- Email:
security@ndtdigital.com.br - GitHub Private Vulnerability Reporting, when enabled for the affected repository.
Please do not disclose security-sensitive information through:
- public GitHub Issues;
- public GitHub Discussions;
- public pull requests;
- public comments;
- social networks or other public communication channels.
If you are unsure whether an issue has security impact, please use the private security channel.
When possible, include enough information for us to understand and reproduce the issue.
Useful information may include:
- affected repository, product, service, domain, or endpoint;
- affected version or commit, when known;
- description of the vulnerability;
- steps to reproduce;
- expected and observed behavior;
- potential security impact;
- proof of concept, when appropriate;
- relevant logs, screenshots, requests, or responses;
- suggested mitigation, if available.
Please avoid including unnecessary personal information, credentials, access tokens, private data, or unrelated sensitive information.
This policy applies to software, repositories, services, APIs, websites, and infrastructure maintained by NDT digital unless a repository or service explicitly defines a more specific security policy.
Security support depends on the lifecycle and maintenance status of each project.
Actively maintained projects and supported releases receive priority for security fixes.
Deprecated, archived, experimental, or unsupported versions may not receive security updates.
When a project defines a specific supported-version policy, that project-specific policy takes precedence.
After receiving a report, NDT digital may:
- acknowledge the report;
- review and validate the reported behavior;
- assess affected products and versions;
- evaluate severity and potential impact;
- identify mitigation or remediation;
- prepare and validate a correction when necessary;
- coordinate disclosure when appropriate.
Response and remediation times vary according to severity, complexity, affected systems, available mitigations, and operational risk.
We ask reporters to give NDT digital a reasonable opportunity to investigate and remediate a vulnerability before making security-sensitive details public.
Please avoid actions that could:
- compromise accounts, systems, or data;
- cause service disruption;
- modify or destroy information;
- access data beyond what is necessary to demonstrate the issue;
- negatively affect other users;
- expand testing beyond the minimum necessary to validate the vulnerability.
Where appropriate, NDT digital may coordinate disclosure with the reporter after remediation or mitigation.
NDT digital products may depend on third-party software, libraries, platforms, or infrastructure.
If a vulnerability originates exclusively in a third-party component, we may coordinate remediation through dependency updates, configuration changes, mitigations, or the relevant upstream project.
Reports that identify meaningful exposure of an NDT digital product to a third-party vulnerability are still welcome.
Security reports may be submitted in:
- English;
- Portuguese (Brazil).
Security reports:
security@ndtdigital.com.br
General information:
This Security Policy should be read together with the other public NDT digital organization policies: