Security policy
Said and Done archives and republishes public parliamentary data. The project's most important security property is the integrity of the record: what the site says a TD said or how they voted must be exactly what the official source published. Reports touching data integrity are treated with the highest severity.
Reporting a vulnerability
Please report vulnerabilities privately by email to
security@saidanddone.ie. This policy is referenced from the RFC 9116
security.txt served at
/.well-known/security.txt.
We will acknowledge reports within 5 working days. Good-faith research is welcome: we will not pursue action against researchers acting in good faith who avoid privacy violations, data destruction, and service disruption, and who give us reasonable time to remediate before public disclosure. Recognition offered with thanks; this is a non-commercial civic project and there is no bounty programme.
Scope notes
- The service holds no user accounts, no user personal data, and no payment data. The parliamentary data it serves is public.
- Reports that the site's displayed record diverges from the official Oireachtas source are in scope and treated as security reports, even where the cause is a parsing defect rather than an attack.