openfatture

Security Policy

Supported Versions

Version Supported
0.1.x :white_check_mark:

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via email to: info@gianlucamazza.it

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the following information:

Security Best Practices

For Users

  1. Environment Variables
    • Never commit .env files to version control
    • Use strong passwords for PEC accounts
    • Rotate API keys regularly
    • Store certificates securely
  2. Data Protection
    • Enable encryption at rest for sensitive data
    • Use HTTPS for all external communications
    • Regularly backup your database
    • Keep software dependencies updated
  3. Access Control
    • Limit file system permissions
    • Use dedicated service accounts
    • Enable audit logging
    • Monitor for suspicious activity

For Developers

  1. Code Security
    • No secrets in code (use environment variables)
    • Sanitize all user inputs
    • Use parameterized queries (SQLAlchemy)
    • Validate file uploads
    • Implement rate limiting
  2. Dependencies
    • Run safety check regularly
    • Keep dependencies updated
    • Review dependency licenses
    • Use pip-audit or similar tools
  3. Testing
    • Write security tests
    • Test authentication/authorization
    • Fuzz test inputs
    • Check for common vulnerabilities (OWASP Top 10)

Security Features

Implemented

Planned

CLI and integration security

Security controls are applied at the CLI, database, file, email, SDI, payment, and AI integration boundaries. Keep credentials in environment configuration, validate all imported XML/CSV/OFX data, avoid logging secrets, and run the repository security checks before release.

Secure Configuration

Minimal Secure Setup

# .env
# Use strong, unique values!

# Database (use encryption-enabled database in production)
DATABASE_URL=sqlite:///./openfatture.db

# PEC Credentials (rotate regularly)
PEC_ADDRESS=your@pec.it
PEC_PASSWORD=strong_random_password_here
PEC_SMTP_SERVER=smtp.pec.aruba.it
PEC_SMTP_PORT=465

# Encryption Key (generate with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key())")
ENCRYPTION_KEY=your_base64_encryption_key_here

# AI API Keys (if using)
AI_API_KEY=sk-...  # Keep secret!

Production Hardening

  1. Use PostgreSQL with SSL
    DATABASE_URL=postgresql://user:pass@localhost/openfatture?sslmode=require
    
  2. External Secrets Manager
    # Instead of .env, use:
    # - AWS Secrets Manager
    # - HashiCorp Vault
    # - Azure Key Vault
    
  3. Network Security
    • Use firewall rules
    • Restrict outbound connections
    • Use VPN for sensitive operations
  4. Monitoring
    • Enable audit logs
    • Set up alerts for suspicious activity
    • Monitor failed login attempts
    • Track API usage

Compliance

GDPR

OpenFatture handles personal data (client information, financial data). Ensure:

Italian Tax Law

Security Checklist

Before Production

Regular Maintenance

Known Limitations

  1. Digital Signatures - Currently requires external tools
  2. Multi-tenancy - Not yet supported (use separate instances)
  3. API Rate Limiting - Not implemented (use reverse proxy)

Contact


Last updated: 2025-01-09