Security & vulnerability disclosure
Ledger welcomes good-faith reports of security vulnerabilities in Ledger-owned systems. This page describes scope, reporting channels, and coordinated disclosure expectations.
Scope
This policy covers security vulnerabilities in Ledger-owned systems at ledger.vote and associated API endpoints operated by Ledger. Out of scope: third-party services (Supabase, Vercel, Anthropic, Mapbox, FEC API), social engineering targeting individual users, and physical security.
How to report
- Email: security@ledger.vote
- Web form: ledger.vote/contact (select the security category)
Include a description of the vulnerability, steps to reproduce, impact assessment, and an optional non-destructive proof-of-concept.
Safe harbor
Ledger will not pursue legal action against researchers who make a good-faith effort to avoid privacy violations, data destruction, or service disruption; do not access data belonging to other users beyond what is necessary to demonstrate the issue; do not publicly disclose before the coordinated disclosure window below; and report exclusively through the channels above.
Response timeline (targets)
- Acknowledgment: 3 business days
- Initial assessment: 10 business days
- Fix or mitigation plan: 30 business days for High severity; 90 days for Medium
- Public disclosure coordination: after fix deployed or mitigating control documented
Severity uses CVSS-style reasoning adapted to civic-data impact. Political-opinion data and address-derived jurisdiction are treated as sensitive.
Coordinated disclosure
Ledger prefers coordinated disclosure. Reporters agree to allow reasonable time for remediation before public disclosure. Ledger may request embargo extension with justification. Ledger may publish a brief acknowledgment of fixed issues without identifying the reporter, unless the reporter requests attribution.
Recognition
Ledger does not operate a paid bug bounty at Alpha. Valid reports may receive public acknowledgment at the reporter's discretion once resolved.
Machine-readable contact file: /.well-known/security.txt. Effective 2026-05-28.