Skip to content

Security: harnumaix/cripta-identity-framework

SECURITY.md

Security Policy: Cripta Identity Framework (CIF)

πŸ›‘οΈ Our Philosophy

CIF is built on the "Path of Least Resistance" but with "Zero Compromise" on integrity. We believe in transparency regarding our cryptographic choices.


⚠️ Disclosure Policy

Do not report security vulnerabilities via public GitHub issues.

If you discover a potential security flaw, please help us protect the community by reaching out via the secure contact methods listed on my GitHub profile: πŸ‘‰ Social Links

We aim to acknowledge all valid reports within 48 hours.


πŸ“¦ Supported Versions

Version Supported
v1.x βœ… Active (Stable)
< v1.0 ❌ Not Supported

πŸ” Audit Status

CIF is currently in an Experimental Stable phase.

  • External Audit: Pending funding/collaboration.
  • Internal Audit: Continuous. The core engine is self-verified via ML-DSA signatures.

🚫 Zero-Access Guarantee

The author and the framework itself have zero access to your Master CID, PIN, or derived secrets. All entropy remains local to your environment.





There aren't any published security advisories