To report a vulnerability in any Anchored Receipts specification or reference implementation, email security@dekimu.com.
Do not file a public issue for security-sensitive reports.
This policy covers:
- Specification documents in this repository (ambiguities that could lead to insecure implementations)
- Conformance test vectors (vectors that, if followed, would produce insecure verifier behaviour)
- Governance and contribution processes (if they could be exploited to land malicious spec changes)
Implementation bugs belong in the relevant implementation repo (e.g., dekimuhq/apr-verifier).
We follow coordinated disclosure with a 90-day window. We will acknowledge receipt within 48 hours and provide a timeline within 7 days.