Security Policy

Reporting a vulnerability

Please use GitHub private vulnerability reporting rather than opening a public issue.

We aim to acknowledge within 3 business days and to ship a fix or a documented mitigation within 90 days, coordinating disclosure with you.

Scope — what we consider a vulnerability

MassingViewer processes files that arrive from outside the organisation using it: IFC models from consultants, PDFs from subcontractors, DXF underlays, and drawing SVG. Handling of untrusted input is explicitly in scope, not treated as user error.

In scope:

Out of scope:

Supported versions

Pre-1.0.0: only the latest 0.x release. After 1.0.0, the current major and the previous minor.

What we do on our side