security/README.md
A guide for practicing safe web.
Security is important, and you can't practice these guidelines without understanding them. Make sure you understand each guideline, why it exists, and how to follow it.
Failing to follow these guidelines will likely put you, your team, and your deployed services at risk of compromise or loss of privacy.
The following guidelines apply to how you as an individual secure access to your systems (laptop, accounts, etc.) and communication (email, etc.).
See protecting personal or identifying information.
The following guidelines apply to how we physically secure our laptops and mobile devices that may contain customer or user data.
The application security guidelines apply to how we develop software on behalf of ourselves and clients.
The following guidelines apply to how we handle security incidents.
When someone finds a possible security issue in our software, we encourage them to report it to our [email protected] email address.
When an email comes in through this channel, reply quickly with confirmation (and CC [email protected] so others know that it has been handled) and the information for the thoughtbot PGP key, which is located at https://thoughtbot.com/security.
When an encrypted message comes in, post the exchange to a new Hub Message in the security interest, and keep the thread updated with new messages
as they appear.
Further discussion of security takes place in the Security Basecamp.