security policy
coordinated vulnerability disclosure
all security research follows coordinated vulnerability disclosure (cvd).
reporting a vulnerability
if you find a security issue in 1seal:
- do not open a public GitHub issue
- email: security@1seal.org
-
include:
- description of the vulnerability
- steps to reproduce
- potential impact
- suggested fixes (optional)
what to expect
- acknowledgment target: 48 hours (not a guarantee)
- initial assessment target: 7 days (not a guarantee)
- regular updates while remediation is in progress
- credit in advisory (unless you prefer anonymity)
scope
this policy covers:
- 1seal specifications and protocols
- documentation that could lead to security issues
out of scope:
- social engineering attacks
- denial of service attacks that don't exploit a bug
- issues in dependencies (report to upstream)
disclosure timeline for reports about 1seal
targets (not guarantees):
- fix critical issues within 14 days
- fix high severity within 30 days
- fix medium/low within 90 days
disclosure timing is coordinated with reporters. disclosure does not occur before fixes are available unless there's active exploitation.
our research
The research disclosure policy governs findings reported by 1seal to other projects, including coordination, publication timing and exceptions. That policy takes precedence for outbound research; the targets above concern reports about 1seal itself, not LMV appeal handling.
The research catalogue records publicly verifiable evidence, including advisories, commits, pull requests and releases. Public code, released fixes and attribution are separate claims; an entry does not imply all three. Unpublished report details are not made public merely because a related fix exists.