generated: '2026-08-13' method: searched probe: true source: https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md note: >- probe-security-programs.py found nothing (vdp=none) because Postiz serves no /.well-known/security.txt and no /security page on postiz.com. The program is real and substantial — it lives in the repository SECURITY.md and on a dedicated advisory platform. This artifact is the searched upgrade over the empty probe. policy: - https://github.com/gitroomhq/postiz-app/blob/main/SECURITY.md - https://postiz.gadvisory.org/advisories report_intake: - https://postiz.gadvisory.org/request contact: - egelhaus@ennogelhaus.de contact_note: >- Maintainer email is for urgent reports only; all routine security correspondence goes through the GAdvisory request form. GitHub private vulnerability reporting is DISABLED for gitroomhq repositories — GitHub Security Advisories are a publishing mirror only. bug_bounty: program: false platform: null note: No paid bounty. Coordinated disclosure with credit in the published advisory and CVE record. cna: is_cna: true scope: Products listed in the SECURITY.md scope section lifecycle: Reserve on confirmation, share the reserved ID with the reporter, publish with the advisory and the fixed release advisories: https://postiz.gadvisory.org/advisories note: >- Postiz operates as a CVE Numbering Authority for its own products — an unusually mature posture for a company of this size, and a stronger signal than a security.txt. scope: in_scope: - github.com/gitroomhq/postiz-app core repository - All gitroomhq repositories that are official Postiz components, tooling or integrations - Official Postiz container images on GHCR under gitroomhq - Official Postiz CLI tools and npm packages (npm org @postiz) - Postiz Cloud infrastructure and services (API, frontend, configuration) - Plugins maintained within the gitroomhq organization out_of_scope: - Third-party dependencies unless Postiz's own use is independently exploitable - User-hosted infrastructure misconfiguration on self-hosted instances - Denial-of-service, brute force and resource exhaustion absent a missing common defense - Social engineering, phishing, self-XSS - Missing hardening with no demonstrated exploitable impact - End-of-life or unsupported versions disclosure_model: coordinated (private until a fix or mitigation ships) timelines: initial_acknowledgment: 72 hours triage_verification: 7 days after acknowledgment critical_remediation: 90 days after triage non_critical_remediation: 180 days after triage cve_publication: within 24 hours of the remediation release ai_reports_policy: >- LLM-generated reports without meaningful human analysis — typically lacking a working proof of concept, reproducible steps or accurate impact assessment — are closed without detailed response. AI-assisted analysis is welcome when validated by the reporter with a PoC, repro steps and impact assessment. recent_advisory_example: id: PSA-2026-NWZN9J fixed_in: v2.21.10 released: '2026-06-22' source: https://github.com/gitroomhq/postiz-app/releases security_txt: served: false note: >- Recommendation for the provider — publish /.well-known/security.txt on postiz.com and api.postiz.com with Policy and Contact pointing at the GAdvisory form. The program already exists; only the RFC 9116 advertisement is missing. evidence: - {source: 'https://raw.githubusercontent.com/gitroomhq/postiz-app/main/SECURITY.md', status: 200, kind: security-policy, fetched: '2026-08-13'} - {source: 'https://postiz.gadvisory.org/request', status: 200, kind: disclosure-intake, fetched: '2026-08-13'} - {source: 'https://postiz.gadvisory.org/advisories', status: 200, kind: advisory-database, fetched: '2026-08-13'} - {source: 'https://postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'} - {source: 'https://api.postiz.com/.well-known/security.txt', status: 404, kind: security-txt, fetched: '2026-08-13'} trust_center: present: false note: >- trust.postiz.com and security.postiz.com do not resolve; postiz.com/security and postiz.com/compliance both return 404. No trust-center artifact is written and no TrustCenter or Compliance pointer is emitted. maintainers: - FN: Kin Lane email: kin@apievangelist.com