Vulnerability disclosure

Updated

The canonical policy is kryptic.dev/security/disclosure. RFC 9116 security.txt is at kryptic.dev/.well-known/security.txt.

Report

Email [email protected]. Do not open a public GitHub issue, pull request, or discussion.

Include the product (cloud, daemon, encryption engine, language package, operator), a version or commit if you have one, why it matters, and steps that do not harm other customers.

What we will not promise

  • There is no paid bug bounty.
  • Acknowledgement within five business days is a target, not an SLA.
  • Kryptic is not a CVE Numbering Authority. We do not assign CVE IDs.

CVE coordination

When a confirmed issue in a released, supported component warrants a CVE:

  • Open source (engines, daemon, packages, operator): we open a GitHub Security Advisory and request a CVE through GitHub. GitHub's CNA assigns the ID.
  • Cloud platform: we request a CVE from MITRE or another CNA that will take it.

We do not request CVEs for unreleased code, theoretical findings with no practical impact, third-party software we do not ship, or self-hosted misconfiguration.

We ask that you wait until a fix is published, or 90 days after our first acknowledgement, whichever comes first. If we go silent, you are not bound by that request.

Encryption

The operator summary is in Encryption. The wire-level writeup is For geeks. Each engine repository also ships SECURITY.md. We do not use the phrase "zero-knowledge" until an independent cryptographic review is published.