EvoGuard is currently in the MVP / design-partner pilot phase. Only the latest commit on main is supported with security fixes.
| Version | Supported |
|---|---|
main (latest) |
β |
| Tagged releases | β (when available) |
| Older commits | β |
We take security vulnerabilities seriously. Please follow this process:
Do NOT file a public issue. Instead, email security@evoguard.app with:
- A description of the vulnerability
- Steps to reproduce
- Affected components
- Proof of concept (encrypted if sensitive β use our PGP key below)
Use the Security Report issue template. This is appropriate for:
- Defense-in-depth suggestions
- Hardening ideas
- Theoretical concerns
- Issues already documented in our working threat model
| Step | Target SLA |
|---|---|
| Acknowledge receipt | 24 hours |
| Initial assessment | 72 hours |
| Triage & severity assignment | 5 business days |
| Fix or mitigation plan | 30 days (high), 90 days (medium), 180 days (low) |
| Coordinated public disclosure | 90 days after fix released |
For encrypted vulnerability reports, use the following PGP key:
EvoGuard Security <security@evoguard.app>
Fingerprint: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
Note: The actual PGP key will be published before the production launch.
We acknowledge security researchers who responsibly disclose vulnerabilities:
- Hall of Fame β listed on our security page (with permission)
- Swag β EvoGuard sticker pack + t-shirt for confirmed high-severity reports
- Bounty β monetary rewards for critical vulnerabilities in production (after launch)
- The EvoGuard demo dashboard (
github.com/modarresi1913/Evoguard) - Production backend components (when available)
- The GitHub App integration
- The web dashboard
- API endpoints
- Authentication & authorization
- Tenant isolation
- Encryption implementation
- Vulnerabilities in third-party dependencies (report to upstream maintainers)
- Social engineering attacks against EvoGuard employees
- Physical attacks against EvoGuard infrastructure
- DoS attacks against the production service (use responsible disclosure)
- Issues requiring physical access to a user's device
- Bugs in unsupported versions
See the Security & Privacy section of the README for our published working threat model and security policies.
We follow Google's Project Zero disclosure guidelines:
- 90-day disclosure deadline
- Automatic publication of the vulnerability report after the deadline
- Extensions granted on a case-by-case basis
- Security email: security@evoguard.app
- General inquiries: hello@evoguard.app
- GitHub Issues: github.com/modarresi1913/Evoguard/issues