Skip to content

Security: jumpmasterrt/CTGEngage

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are currently provided for the latest production release of CTG Engage.

Version Supported 1.0.x Yes Earlier versions No

Reporting a Security Issue

Please do not open a public GitHub issue for security vulnerabilities, privacy concerns, or issues that could expose visitor information.

Security reports should be sent privately to the project maintainer.

When reporting an issue, include as much of the following information as possible:

  • CTG Engage version
  • Hardware and operating system
  • Description of the issue
  • Steps required to reproduce it
  • Potential impact
  • Relevant logs or screenshots, with personal information removed

Please do not include real visitor contact information, credentials, access tokens, passwords, or other sensitive data in a report.

Visitor Data and Privacy

CTG Engage may collect and store visitor contact information locally as part of its event engagement workflow.

Potential vulnerabilities involving:

  • unauthorized access to stored contacts
  • unintended disclosure of visitor information
  • CSV export behavior
  • local data persistence
  • administrative controls
  • kiosk escape or unauthorized system access

should be treated as security issues and reported privately.

Responsible Disclosure

Please allow the project maintainer an opportunity to investigate and address a reported vulnerability before publicly disclosing technical details.

Scope

This policy applies to CTG Engage software and the supported ExpoPi reference deployment.

Third-party operating systems, browsers, libraries, hardware, and external services may have their own security policies and reporting procedures.

There aren't any published security advisories