Coordinated disclosure

Security

Report vulnerabilities privately. Do not include private keys or exploit unrelated systems.

Report

Email [email protected] with affected endpoint, impact, reproduction steps, and a safe contact method. We will acknowledge reports when the mailbox is operational.

Safe testing

Use the smallest proof necessary. Do not access other users’ data, degrade service, perform denial-of-service testing, or publish an unresolved issue before coordination.

Verification

Signed application receipts publish verification keys at /v1/receipts/jwks.json.