Security Policy
Responsible disclosure guidelines for vote.machineassurance.org
Scope
This policy applies exclusively to the domain vote.machineassurance.org and its subdomains. It covers vulnerabilities in the Machine Assurance Institute's Open Source the Vote Initiative intake form and supporting infrastructure hosted on that domain.
This policy does NOT apply to:
- Third-party services or infrastructure (including email providers, SMS carriers, cloud services, or CDN providers)
- Domains outside vote.machineassurance.org
- Content or behavior of linked external sites
Good Faith
Machine Assurance Institute operates this policy in good faith and commits to:
- No legal action. We will not pursue legal action against researchers who discover and report vulnerabilities in accordance with this policy.
- No prosecution. Reporters will not be referred to law enforcement for participation in authorized security research within the scope defined here.
- Prompt response. We will acknowledge receipt of a report within 2 business days and provide regular updates on our progress.
- Fair treatment. We evaluate all reports on their technical merits, without regard to the reporter's background or organization.
What Is In Scope
We welcome reports on technical vulnerabilities affecting the security or privacy of vote.machineassurance.org, including:
- Cryptographic failures
- SQL injection, command injection, or template injection
- Cross-site scripting (XSS) or cross-site request forgery (CSRF)
- Broken authentication or session management
- Insecure direct object references (IDOR) or privilege escalation
- Information disclosure or data exposure
- Server misconfigurations affecting confidentiality or integrity
- Vulnerabilities in upstream dependencies
- API security issues
What Is Out of Scope
The following are explicitly out of scope and will not be acted upon:
- Social engineering, phishing, or pretexting — testing against staff, users, or third parties
- Physical attacks or environmental controls — tampering with infrastructure, badges, locks
- Denial of service (DoS) — any test that degrades service availability for legitimate users
- Attacks on third-party services — vulnerabilities in Cloudflare, hosting providers, email services, or SMS carriers
- Testing on production live election systems — only testing within our controlled intake form environment is authorized
- Spam or automated scanning — indiscriminate vulnerability scanners sent without consent
- Reports without technical detail — vague claims without reproduction steps
How to Report
Report security vulnerabilities by email to security@machineassurance.org.
Include in your report:
- A clear, descriptive title
- The type of vulnerability (e.g., XSS, IDOR, misconfiguration)
- Affected component or endpoint
- Step-by-step reproduction instructions
- Proof of concept (code, screenshots, or video if helpful)
- Impact assessment (what an attacker could do)
- Your contact information and PGP key (if desired)
Do not:
- Test against production systems or live data without authorization
- Publicly disclose the vulnerability before we have had time to respond
- Access, modify, or delete any data beyond what is necessary to demonstrate the vulnerability
- Intentionally harm users or disable services
Coordinated Disclosure Timeline
We follow a 90-day coordinated disclosure window:
- Day 0: You report a vulnerability
- Day 2: We acknowledge receipt and provide an initial assessment
- Days 2–30: We work to understand, reproduce, and plan a fix
- Days 30–60: We implement and test the fix
- Days 60–90: We deploy the fix and prepare a public disclosure
- Day 90: We publish a security advisory and notify you that we are doing so (unless you request to remain anonymous)
If you discover a critical vulnerability affecting election integrity or user data, we may accelerate this timeline. If we need more time for complex remediation, we will discuss an extension with you.
Do not publicly disclose the vulnerability before Day 90 without our explicit written permission.
Recognition and Rewards
While the Machine Assurance Institute does not currently offer a formal bug bounty program, we recognize responsible researchers in the following ways:
- Public acknowledgment in security advisories (with your permission)
- A mention on this page as a security contributor (if you opt in)
- Priority consideration for roles or collaboration opportunities within the Open Source the Vote Initiative
Safe Harbor Example
Authorized: You discover a CSRF vulnerability in the intake form. You craft a proof-of-concept HTML file that demonstrates the issue (without submitting any actual data) and report it with reproduction steps.
Unauthorized: You write a script that repeatedly submits test data to the form, causing service disruption for legitimate users. Or you attempt to gain administrative access to the underlying infrastructure.
Questions or Clarifications
If you are unsure whether something is in scope or have questions about this policy, email security@machineassurance.org first. We would rather clarify boundaries than have a researcher inadvertently step outside them.
Last updated: August 7, 2026.
Effective for: vote.machineassurance.org and all subdomains.
Contact: security@machineassurance.org