Interface language: English.

Accessibility & relay services
← Utah Resource Navigator

Security & vulnerability reporting

Reporting a problem

Send security reports to communications@utahbar.org. This is the Utah State Bar's general communications address. It is not a dedicated security mailbox and is not described here as continuously monitored.

Published reporting policy URL: https://original-legalresourcemap.lovable.app/security. The same values are published in machine-readable form at /.well-known/security.txt.

No safe-harbor or authorization commitment is made on this page, and no acknowledgement or response time is promised. Any legal safe-harbor language must be drafted and approved by counsel before it is published.

Protections currently in place

External CAPTCHA (Cloudflare Turnstile) is not enabled today. A verification hook exists in the sign-in path and activates only when the operator supplies a secret key; until then it is not claimed as a protection.

Scope of the sign-in throttle. Our administrator sign-in screen always submits through a server-controlled path that applies attempt limits and automation checks. That is an application-level control: the hosted authentication API is itself a public endpoint, so requests made directly to it, outside this site, are governed by the authentication provider’s own rate limiting and CAPTCHA settings rather than by our throttle. We state this scope plainly rather than overstating the protection.

Ask URN