Coordinated disclosure
Help us keep Peptide Atlas secure.
We welcome good-faith reports about security issues affecting any Peptide Atlas domain or this project’s public code.
How to report
Use the repository’s private security advisory channel when available. If you cannot access it, use the corrections page and identify the message as a security report.
Safe research expectations
Use only the minimum testing needed to demonstrate an issue. Do not access, alter, retain, or disclose other people’s data; disrupt availability; run denial-of-service tests; send spam; use social engineering; or demand payment. A report does not authorize testing that would otherwise be unlawful.
What to expect
We will acknowledge a usable report when a monitored contact channel is available, assess severity, work toward a proportionate fix, and coordinate public disclosure when appropriate. Please allow a reasonable remediation period before publishing details.
Current safeguards
The public properties are static sites. Server credentials are limited to the private publishing workflow, automated scans check for accidental exposure, dependencies are monitored, and publication records are mirrored to a private integrity control layer.