Vulnerability Disclosure Policy
How to report a security weakness, bug, or functional issue in Devs.Nepal — and the protections you get for reporting responsibly.
Why this policy exists
Devs.Nepal welcomes good-faith research from anyone who finds a security weakness, bug, or functional issue in our platform. This policy tells you what is in scope, how to report, what response to expect, and the protections we offer researchers who report responsibly.
Scope
In scope: pmdevcore.gov.np and any sub-path served from it; the API at /api/*; the agent install script at /agent/*; our self-hosted Gitea at git.pmdevcore.gov.np. Out of scope: third-party services (Google, GitHub, etc), social-engineering staff, denial-of-service / volumetric attacks, physical security of OPMCM data centres.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will not initiate or recommend any legal action against you. You may test with your own account or a freshly-created test account; you may inspect, read, and modify data that belongs to you; you may NOT access, modify, or destroy data belonging to other users.
How to report
We strongly prefer reports through the form at /report — it routes the submission directly into our triage queue and gives you a tracking ID immediately. Security reports may be filed anonymously; bug and functional reports require signing in.
If you must report by email, send to it.steeringcommittee@opmcm.gov.np with subject prefix [SECURITY]. PGP available on request.
Please include: a short title, clear description, steps to reproduce, the affected URL or component, your environment (browser, OS, build), and (for security) the impact you believe an attacker could achieve.
What you can expect from us
- Acknowledgement within 3 business days.
- Initial triage decision (accepted / duplicate / out of scope / need more info) within 7 business days.
- Status updates whenever the state of your report changes.
- Coordination on disclosure timing — we ask for a default 90-day private window before public disclosure for security findings; we will tell you if we need longer and why.
- Public credit on our acknowledgements page if you ask for it.
What we ask of you
- Don't access, modify, or destroy data that doesn't belong to you.
- Don't disrupt the service for other users (no DoS, no high-rate scanning).
- Don't disclose the finding publicly until we have either fixed it or 90 days have elapsed, whichever comes first.
- Don't ask for payment — Devs.Nepal does not run a bug bounty programme. We offer recognition, not money.
Acknowledgements
A roll of researchers who have helped harden Devs.Nepal is maintained at /security/hall-of-fame. To opt in, tick the credit box on the report form.