Skip to content

Security: vturrojas/surety

Security

SECURITY.md

Security Policy

Current status

Surety is presently a research design repository. It does not yet provide a production security control, released harness, or supported deployment.

This repository is documentation-first; current security reports concern repository content and contribution pathways, not a hosted production service.

Reporting a vulnerability

Do not open a public issue for a vulnerability that could create immediate risk to a real system or disclose sensitive information.

Until a dedicated project address is established, contact the maintainer through the private contact method listed on the GitHub profile. Include:

  • the affected document, case, or code path
  • the security impact
  • reproduction steps using a safe or synthetic target
  • relevant logs or evidence with secrets removed
  • any suggested mitigation
  • whether the issue affects another project that requires coordinated disclosure

Receipt will be acknowledged as soon as practical. Validation, disclosure timing, and remediation will be coordinated based on impact and the needs of affected maintainers.

Safe research boundary

Reports and benchmark contributions must be based on systems the researcher owns or is explicitly authorized to test.

Do not provide:

  • live credentials, tokens, keys, or session material
  • classified, controlled, proprietary, or operationally sensitive information
  • personal data unrelated to the report
  • instructions that require testing an unauthorized third-party system
  • public zero-day details before affected parties have a reasonable opportunity to respond

No security warranty

The presence of a passing benchmark result does not establish that a system is secure. Surety cases test defined properties under stated conditions. They cannot establish the absence of other failure modes.

There aren't any published security advisories