Security policy
Coordinated vulnerability disclosure for eTVET Ethiopia (national TVET platform).
Report a vulnerability
Email security@etvet.et or see security.txt.
- Include URL, description, steps to reproduce, and impact.
- Do not access or modify live trainee/staff data beyond what is needed to demonstrate the issue.
- Do not perform denial-of-service or destructive testing against production.
- Allow reasonable time for remediation before public disclosure.
Scope
In scope: https://etvet.et web application, public verify/register, staff API, and related infrastructure we operate.
Out of scope: social engineering of MoLS/college staff, physical attacks, and third-party services we do not control.