Skip to main content

Security Disclosure

Security vulnerabilities in PTI specifications, conformance tooling, or widely deployed reference implementations MUST be handled through coordinated disclosure. This protects subjects and institutions while giving implementers time to patch.

This policy covers ecosystem-level disclosure. Operator incident response remains governed by RFC-008 Security and platform-specific runbooks.

Scope

In scopeOut of scope
Normative flaws enabling bypass of RFC-008 controlsIndividual tenant misconfiguration
Cryptographic weaknesses in specified algorithmsSocial engineering of single bank staff
Trust exchange signature bypassNon-PTI adjacent products
Conformance test suite vulnerabilitiesBug bounty scope of unrelated SaaS
Reference implementation CVEs with spec implicationsGeneric IT vulnerabilities without PTI impact

Reporting

Researchers and implementers SHOULD report to:

security@pti-standard.org (placeholder — operational address published by SRG)

Reports SHOULD include:

  • Description and reproduction steps
  • Affected RFCs or components
  • Impact assessment (confidentiality, integrity, availability, subject privacy)
  • Suggested remediation if known
  • Disclosure preference and embargo request

Reports MUST NOT include live subject personal data. Use synthetic test identities only.

Roles

RoleResponsibility
ReporterGood-faith disclosure; avoids public exploit during embargo
SRGTriage, severity, CVE assignment, coordination
Working GroupSpec errata or RFC revision
ImplementersPatch deployment per severity SLA
StewardshipInfrastructure for advisory publication

Severity and timelines

SeverityExampleSpec fix targetImplementer patch targetPublic disclosure
CriticalLookup auth bypass exposing cross-context data7 days30 daysAfter patch or 90 days max
HighSignature verification flaw in exchange14 days60 daysCoordinated
MediumDenial of service on registry API30 days90 daysWith release
LowInformation leak in error messagesNext scheduledNext scheduledWith release

Active exploitation MAY shorten embargoes at SRG discretion with same-day implementer notice.

Specification vs implementation flaws

Finding typeAction
Spec silent / wrongErrata or RFC revision; SRG MUST document correct behavior
Spec clear; implementation wrongCVE to implementer; conformance tests SHOULD add regression
BothSpec fix first; CVE notes affected versions

Reference implementation issues MUST NOT delay spec fixes when the spec is ambiguous.

Embargo rules

  • Default embargo: 90 days from report acknowledgment
  • Extensions MAY be granted once by mutual agreement
  • Reporters SHOULD receive credit unless anonymity requested
  • Public disclosure MUST include: CVE ID, affected versions, fixed versions, workaround if any

Safe harbor

Good-faith security research consistent with this policy SHOULD NOT face legal action from stewardship organizations participating in the program. Safe harbor does not authorize access to production subject data or violation of applicable law.

Post-disclosure

After publication, the Working Group SHOULD:

  1. Update conformance tests with regression cases
  2. Review related RFCs for similar patterns
  3. Publish lessons learned in SRG minutes (redacted)