Skip to main content
Ledger is nonpartisan. Ledger does not endorse candidates, campaigns, or parties.

Security & vulnerability disclosure

Ledger welcomes good-faith reports of security vulnerabilities in Ledger-owned systems. This page describes scope, reporting channels, and coordinated disclosure expectations.

Scope

This policy covers security vulnerabilities in Ledger-owned systems at ledger.vote and associated API endpoints operated by Ledger. Out of scope: third-party services (Supabase, Vercel, Anthropic, Mapbox, FEC API), social engineering targeting individual users, and physical security.

How to report

Include a description of the vulnerability, steps to reproduce, impact assessment, and an optional non-destructive proof-of-concept.

Safe harbor

Ledger will not pursue legal action against researchers who make a good-faith effort to avoid privacy violations, data destruction, or service disruption; do not access data belonging to other users beyond what is necessary to demonstrate the issue; do not publicly disclose before the coordinated disclosure window below; and report exclusively through the channels above.

Response timeline (targets)

  • Acknowledgment: 3 business days
  • Initial assessment: 10 business days
  • Fix or mitigation plan: 30 business days for High severity; 90 days for Medium
  • Public disclosure coordination: after fix deployed or mitigating control documented

Severity uses CVSS-style reasoning adapted to civic-data impact. Political-opinion data and address-derived jurisdiction are treated as sensitive.

Coordinated disclosure

Ledger prefers coordinated disclosure. Reporters agree to allow reasonable time for remediation before public disclosure. Ledger may request embargo extension with justification. Ledger may publish a brief acknowledgment of fixed issues without identifying the reporter, unless the reporter requests attribution.

Recognition

Ledger does not operate a paid bug bounty at Alpha. Valid reports may receive public acknowledgment at the reporter's discretion once resolved.

Machine-readable contact file: /.well-known/security.txt. Effective 2026-05-28.