Information Security Policy

Last updated 10 August 2026.

Principles

Reporting a vulnerability

Report vulnerabilities however suits you. A public issue on GitHub is welcome, and so is private email to petri.koistinen@refineid.fi. You will receive an acknowledgement within a month.

Scope and support

The policy covers the ReFineID applications and the services at refineid.fi. The latest released versions are supported. Machine-readable contact details are published at /.well-known/security.txt.