Skip to content

Security: vikrant-project/soulbrowser

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

  1. Do NOT open a public issue
  2. Email: security@soulbrowser.dev
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 7 days
  • Resolution: Depends on severity

Severity Levels

Severity Response Time Examples
Critical 24-48 hours Remote code execution, data leak
High 7 days Authentication bypass, XSS
Medium 30 days Information disclosure
Low 90 days Minor issues

Security Best Practices

When using Soul Browser:

  1. Keep Updated: Always use the latest version
  2. Verify Downloads: Check SHA-256 checksums
  3. Use HTTPS: Enable HTTPS-only mode
  4. Review Extensions: Only install trusted extensions
  5. Proxy Security: Use secure proxy connections

Disclosure Policy

  • We practice coordinated disclosure
  • Credit will be given to reporters (unless anonymity requested)
  • We do not pursue legal action against good-faith security researchers

Security Features

Soul Browser includes:

  • Automatic HTTPS upgrading
  • Certificate validation
  • XSS protection
  • Mixed content blocking
  • Cryptojacking blocker
  • Phishing protection

Thank you for helping keep Soul Browser secure!

There aren't any published security advisories