Reporting
Use the structured Contact security path. Include the affected surface, reproducible impact, and a safe way to reach you if you choose. Do not include live credentials, private user data, payment-card data, or exploit material in a public channel.
- The current machine-readable policy is at /.well-known/security.txt
- Security cases receive restricted routing
- Good-faith reports are not routed into editorial coverage or marketing
Controls
High-risk commands require authenticated AAL2 staff roles, same-origin requests, idempotency, optimistic versions, reasons, command receipts, audit records, and independent approval where policy requires it. Hub mutations additionally require body-bound signatures, replay protection, and durable acknowledgement.
- Least privilege and fail-closed configuration
- Encrypted restricted fields and token hashes
- Append-only audit and governance evidence
- Rate limits, abuse controls, revocation, and bounded retention
Evidence boundary
A public security statement is not proof of production effectiveness. Release certification records automated checks, independent review, key-rotation evidence, incident exercises, dependency posture, and current exceptions without publishing exploitable detail.