Skip to content

Security: Cubits11/ghost-ark

SECURITY.md

Security Policy

Ghost-Ark is an experimental reference implementation. It is unaudited and must not be used as the sole security boundary for production systems.

Reporting

Report vulnerabilities through GitHub Security Advisories for this repository. If a separate maintainer contact is later listed by the project owner, use that contact for coordinated disclosure.

Boundaries

  • No compliance certification is claimed.
  • No bug bounty is offered unless a written bounty policy is added.
  • Mock, schema-only, and research interfaces are not cryptographic proof of runtime behavior.
  • Live AWS deployment, Nitro attestation, KMS, and zk proof claims require checked-in implementation evidence and explicit review.

There aren't any published security advisories