Skip to content

Security: edycutjong/noxsafe

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
latest (main)

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities. Instead, report them privately:

You'll get an acknowledgment within 48 hours and a resolution timeline after triage. Please give us a reasonable window to patch before public disclosure.

Scope Notes

NoxSafe deploys only to Ethereum Sepolia with throwaway keys — never mainnet. The known trust boundaries and residual risks (operator authority, public float, client-side plaintext) are documented candidly in the project README.md ("Honest limitations") and SPEC.md (invariants I1–I4).

There aren't any published security advisories