Security policy · version 1.1

Security and incident response

Security reports are welcome when they protect visitors and stay within this website. This page publishes safe operational information without publishing credentials, defensive secrets, private reports, or instructions that would make the site easier to attack.

Current public security posture

Limits: these controls reduce risk; they do not prove that the site is breach-proof, independently penetration tested, SOC 2 certified, HIPAA compliant, or compliant with every security law.

Good-faith vulnerability reporting

Use the Corrections Management human form, choose Privacy or safety concern, and begin the subject with Security report. Include the affected URL, date and time, browser or tool, expected result, observed result, minimal reproduction steps, and a non-sensitive proof. Do not paste credentials, private user data, live session cookies, exploit payloads that reveal personal information, or another person’s report.

In scope

Not authorized

If a test unexpectedly exposes personal information or a credential, stop, do not retain or redistribute it, record only the minimum non-sensitive evidence, and report the event. A report does not authorize conduct prohibited by law or by a third party’s rules.

Incident severity

LevelExampleFirst response
CriticalActive account takeover, exposed credential, ongoing disclosure of private tickets, or an AI safety failure creating imminent risk.Disable the affected feature, preserve evidence, protect people, and notify Christopher immediately.
HighUnauthorized access path, material provider breach, stored injection, or repeatable safety-control bypass.Contain access, assess data and users affected, fix or isolate, and begin notification analysis.
ModerateLimited misconfiguration, non-sensitive information exposure, accessibility barrier blocking a key task, or misleading policy-to-code mismatch.Document, prioritize, correct, test, and update the affected notice.
LowHardening suggestion or issue with no demonstrated confidentiality, integrity, availability, safety, or access impact.Record and review during normal maintenance.

Incident lifecycle

  1. Receive and preserve: timestamp the report, restrict access, preserve useful evidence, and avoid destroying logs or records needed for investigation.
  2. Triage: identify affected feature, data, people, providers, time range, severity, and whether the report is continuing.
  3. Contain: use the narrowest effective measure—feature disable, session invalidation, access restriction, provider escalation, or content removal—without changing unrelated credentials or systems.
  4. Investigate and remediate: determine cause and scope, fix it, test the fix, and check for the same pattern elsewhere in this website.
  5. Notification analysis: Christopher obtains qualified legal guidance for applicable federal, state, health-data, consumer, provider, contractual, law-enforcement, and individual notice duties. Communications must be accurate and must not create additional risk.
  6. Recover: restore only after validation, monitor for recurrence, and keep a rollback path.
  7. Learn: record decisions, update tests and policies, publish a plain-language correction or incident notice when appropriate, and track any remaining action.

Roles and authority

Christopher is the incident decision owner. Andrew may triage, contain within approved website controls, prepare fixes, preserve technical evidence, and maintain corrections. A provider handles its own infrastructure response. Qualified counsel determines legal notification advice; qualified safety, clinical, or accessibility reviewers advise only within their scope. Chris AI has no incident authority.

Reference frameworks

This policy is informed by the NIST Cybersecurity Framework 2.0, NIST SP 800-61 Revision 3, the FTC’s Data Breach Response guide, and CISA’s vulnerability-disclosure guidance. These voluntary references do not certify the implementation.

Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 1.1 · Effective September 5, 2026