Surety is presently a research design repository. It does not yet provide a production security control, released harness, or supported deployment.
This repository is documentation-first; current security reports concern repository content and contribution pathways, not a hosted production service.
Do not open a public issue for a vulnerability that could create immediate risk to a real system or disclose sensitive information.
Until a dedicated project address is established, contact the maintainer through the private contact method listed on the GitHub profile. Include:
- the affected document, case, or code path
- the security impact
- reproduction steps using a safe or synthetic target
- relevant logs or evidence with secrets removed
- any suggested mitigation
- whether the issue affects another project that requires coordinated disclosure
Receipt will be acknowledged as soon as practical. Validation, disclosure timing, and remediation will be coordinated based on impact and the needs of affected maintainers.
Reports and benchmark contributions must be based on systems the researcher owns or is explicitly authorized to test.
Do not provide:
- live credentials, tokens, keys, or session material
- classified, controlled, proprietary, or operationally sensitive information
- personal data unrelated to the report
- instructions that require testing an unauthorized third-party system
- public zero-day details before affected parties have a reasonable opportunity to respond
The presence of a passing benchmark result does not establish that a system is secure. Surety cases test defined properties under stated conditions. They cannot establish the absence of other failure modes.