Resident information
Security and vulnerability reporting
How Spruce protects civic data and how to report a suspected vulnerability safely.
Last updated: 2026-08-29
Security boundary
Spruce is designed around separate environments, least-privilege access, encryption, auditable commands, rate limits, dependency and secret scanning, data classification, kill switches, backups, and deletion-aware restoration. Passing local tests is not a substitute for an independent production security review.
Report a vulnerability
Send a concise description, affected URL or app version, reproduction steps, and potential impact to the security contact below. Do not include live resident data, private evidence, authentication tokens, or destructive proof. Stop testing if you could access another person's data, change civic state, post publicly, or disrupt service.
Good-faith handling
Spruce will acknowledge a monitored report under the published coverage target, investigate it, and coordinate a safe validation path. A formal safe-harbor promise requires counsel approval and is not created by this draft page.