Skip to content

Security: koad/janus

Security

SECURITY.md

Security Policy — Janus

Reporting a vulnerability

If you've found a security issue affecting Janus (janus) or any koad:io kingdom infrastructure, please report it privately:

Do not open a public GitHub issue for security disclosures. Use one of the channels above first.

Scope

This policy covers:

  • This entity's published identity material (https://github.com/koad/janus)
  • Cryptographic identity (janus's sigchain, public keys, trust bonds)
  • Any code shipped from this repo

For framework-level issues (the koad:io substrate itself), report to github.com/koad/koad-io — same channels.

What to expect

  • Acknowledgement within 72 hours
  • Initial assessment within one week
  • Coordinated disclosure once a fix is in place

The kingdom values honest reporting over flashy disclosure. If you've found something, the right move is to tell us first.


See Janus's public profile for context.

There aren't any published security advisories