SourceScore

Security

How we publish claim-integrity metadata, handle disclosed vulnerabilities, and describe the limits of the current service. Read the limits section so you know exactly what we do and don't guarantee at this stage.

Responsible disclosure

If you find a security issue — credential leak, API auth bypass, signature-forgery vector, injection vulnerability, denial-of- service path, or anything else that could compromise the integrity of claim envelopes or user accounts — please report it privately:

  • Email: hello@caslonmedia.com — preferred for first contact.
  • PGP: on request via the email above. A published key fingerprint is not available yet; we will add one here once the rotation cadence is stable.
  • Low-severity reports without an exploit primitive (e.g. dependency-CVE notices) can go to the same address — put “low severity” in the subject. Our source repository is private, so there is no public issue tracker to file against.

We aim to acknowledge within 24 hours and patch high-severity issues within 7 days. Coordinated disclosure preferred; we will credit reporters publicly on this page (opt-in).

Signing & verification

Claim records include an HMAC-SHA256 tag over a canonical JSON serialization. This is SourceScore-issued integrity metadata, not a public cryptographic proof: the shared secret is not published, so a visitor cannot independently recompute the tag.

To check a public record, use HTTPS and refetch it from its canonical SourceScore URL, then inspect its cited evidence. Do not treat the HMAC tag as independently verifiable authentication or as proof of a third party’s endorsement.

Scope of guarantees

  • HTTPS everywhere. All endpoints (/api/v1/* and docs) serve over TLS. Cloudflare edge handles termination. HSTS preload submission is still pending.
  • No PII in logs. We log request paths, status codes, and IP-hashes (not raw IPs) at the edge. We do not log request bodies, response bodies, or API-key plaintext.
  • No user-data sales. We do not operate a paid-account or billing system for this API today.

What we don't (yet) guarantee

Honest scope, per methodology:

  • Catalog claim correctness. Every claim cites primary evidence; 368 of the 384 current claims include two or more sources. Sources can go stale, and the catalog does not guarantee that every claim remains true at every future moment.
  • SOC 2 / ISO 27001. Not certified.
  • Bug bounty program. Not running formally.
  • Public-key verification. Not available today. The current HMAC tag has no public shared secret or public-key proof.

Incident response

If we identify a material issue affecting public claim records, we will update the relevant record or changelog. We do not publish a guaranteed incident-response timeline.

security.txt

Machine-readable contact at /.well-known/security.txt per RFC 9116.