# Security Policies and Procedures This document outlines security procedures and general policies for mountebank. * [Reporting a Bug](#reporting-a-bug) * [Disclosure Policy](#disclosure-policy) * [Comments on this Policy](#comments-on-this-policy) ## Reporting a Bug Thank you for improving the security of mountebank. I sincerely appreciate your efforts and responsible disclosure and will make every effort to acknowledge your contributions. Please report security bugs by emailing me directly at brandon.byars@gmail.com. Following your report, I will investigate and keep you informed of the progress towards a fix and full announcement. Along the way, I may ask for additional information or guidance. Report security bugs in third-party modules to the person or team maintaining the module. You can also report a vulnerability through the [Node Security Project](https://nodesecurity.io/report). ## Disclosure Policy In most cases, I will include a full disclosure in the release notes for the release that fixes the security bug. ## Comments on this Policy If you have suggestions on how this process could be improved please submit a pull request.