Security Banner

Security Center

Security model, platform details, and vulnerability disclosure

Vulnerability Disclosure

Responsible Disclosure

We take security seriously. If you discover a vulnerability, please follow our responsible disclosure process to help keep the network secure.

How to Report

  1. 1
    Email [email protected]

    Use PGP encryption for sensitive details (PGP key available on request)

  2. 2
    Include detailed information

    Steps to reproduce, impact assessment, affected versions

  3. 3
    Allow 90 days for fix

    We’ll work with you to understand and resolve the issue

  4. 4
    Coordinated disclosure

    We’ll credit you (if desired) when the fix is released

Severity Levels

SeverityDescriptionResponse Time
CriticalKey extraction, complete system compromise24 hours
HighAttestation bypass, message forgery3 days
MediumDoS attacks, resource exhaustion7 days
LowInformation disclosure, minor issues30 days