Security Policy

Responsible disclosure guidelines for vote.machineassurance.org

Scope

This policy applies exclusively to the domain vote.machineassurance.org and its subdomains. It covers vulnerabilities in the Machine Assurance Institute's Open Source the Vote Initiative intake form and supporting infrastructure hosted on that domain.

This policy does NOT apply to:

Good Faith

Machine Assurance Institute operates this policy in good faith and commits to:

What Is In Scope

We welcome reports on technical vulnerabilities affecting the security or privacy of vote.machineassurance.org, including:

What Is Out of Scope

The following are explicitly out of scope and will not be acted upon:

How to Report

Report security vulnerabilities by email to security@machineassurance.org.

Include in your report:

Do not:

Coordinated Disclosure Timeline

We follow a 90-day coordinated disclosure window:

If you discover a critical vulnerability affecting election integrity or user data, we may accelerate this timeline. If we need more time for complex remediation, we will discuss an extension with you.

Do not publicly disclose the vulnerability before Day 90 without our explicit written permission.

Recognition and Rewards

While the Machine Assurance Institute does not currently offer a formal bug bounty program, we recognize responsible researchers in the following ways:

Safe Harbor Example

Authorized: You discover a CSRF vulnerability in the intake form. You craft a proof-of-concept HTML file that demonstrates the issue (without submitting any actual data) and report it with reproduction steps.

Unauthorized: You write a script that repeatedly submits test data to the form, causing service disruption for legitimate users. Or you attempt to gain administrative access to the underlying infrastructure.

Questions or Clarifications

If you are unsure whether something is in scope or have questions about this policy, email security@machineassurance.org first. We would rather clarify boundaries than have a researcher inadvertently step outside them.

Last updated: August 7, 2026.
Effective for: vote.machineassurance.org and all subdomains.
Contact: security@machineassurance.org