Security policy

Said and Done archives and republishes public parliamentary data. The project's most important security property is the integrity of the record: what the site says a TD said or how they voted must be exactly what the official source published. Reports touching data integrity are treated with the highest severity.

Reporting a vulnerability

Please report vulnerabilities privately by email to security@saidanddone.ie. This policy is referenced from the RFC 9116 security.txt served at /.well-known/security.txt.

We will acknowledge reports within 5 working days. Good-faith research is welcome: we will not pursue action against researchers acting in good faith who avoid privacy violations, data destruction, and service disruption, and who give us reasonable time to remediate before public disclosure. Recognition offered with thanks; this is a non-commercial civic project and there is no bounty programme.

Scope notes