ATEP

Security policy

Reports of weaknesses in the specification or the reference implementations are welcome. Use GitHub private vulnerability reporting on the repository (report a vulnerability) or email [email protected], with the affected component and version, what you found, and a way to reproduce it. Please do not open a public issue for a vulnerability.

GitHub private vulnerability reporting is enabled on the repository and is the preferred channel. No PGP key is published yet.

Supported

Specification Draft 07, and the 0.1.0 pre-release reference code on the main branch. Earlier drafts are superseded. There is no stable release and no bug bounty.

In scope

Protocol flaws (forgery, replay, downgrade, confusion of envelopes, attestations, revocation lists or log proofs); reference implementations that accept what the vectors reject or the reverse; key or memory handling in the Rust, JavaScript and Python code; log or monitor flaws that hide a forked history.

Out of scope

Examples and the demo, denial of service on the plain HTTP reference log daemon, secrets in JavaScript or Python process memory, third party dependency bugs (report upstream), social engineering of issuers.

Audit status

The project has had no external security audit. The post-quantum crates it uses are young. Treat the code as pre-release.