The TANF Data Portal (TDP) is subject to the ACF Privacy Policy and the HHS Vulnerability Disclosure Policy.
Do not report security vulnerabilities through GitHub Issues, pull requests, discussions, public comments, or unsecured email.
Submit vulnerability reports through the HHS responsible disclosure portal:
https://hhs.responsibledisclosure.com
Reports may be submitted anonymously. The HHS Vulnerability Disclosure Policy describes eligible systems, authorized research, reporting requirements, disclosure timelines, and researcher expectations.
If you believe you have found a vulnerability involving live TDP environments, production data, credentials, tokens, personally identifiable information, or other sensitive information, stop testing and report it through the HHS responsible disclosure portal as soon as possible.
Security reports for this repository and related TDP systems are governed by the HHS Vulnerability Disclosure Policy. Review that policy before testing to confirm which systems and research activities are authorized.
This repository also contains project security and compliance documentation in docs/Security-Compliance.
Security fixes are applied to branches and deployed environments that are actively maintained by the TDP team. Historical, archived, or otherwise unmaintained branches may not receive security updates.
Do not commit secrets, credentials, private keys, access tokens, production data, or personally identifiable information to this repository.
If sensitive information is accidentally exposed, report it through the HHS responsible disclosure portal and follow the project's incident response documentation, including Secret Key Management where applicable.
TDP uses automated checks, dependency monitoring, and security scanning as part of the development workflow. See the project README, CONTRIBUTING, and Security & Compliance Documentation for additional context.