Email ziwei@witnora.com with the subject Witnora security report. This mailbox is the security contact for the public Framework and Hosted Witnora; reports are handled by Ziwei Guo, the maintainer.
Please do not post sensitive vulnerability details in public GitHub issues. For ordinary bugs and documentation questions, use GitHub Issues.
A useful report includes:
- The affected release tag or commit SHA, package, and runtime version.
- A short description of the issue and the authorization, execution, observation, or evidence boundary it affects.
- Minimal reproduction steps using a local sandbox or synthetic data.
- Expected behavior, observed behavior, and potential impact.
Remove credentials, tokens, private keys, personal information, and customer data from your report. If sensitive material is necessary, describe it first so we can agree on an appropriate way to share it. Test only systems and accounts you are authorized to access.
Use the most recent tagged preview on the Releases page, and record its tag and commit SHA when integrating or reporting an issue. The release notes identify its scope and verification evidence.
The Framework is currently an early preview. Preview interfaces may change; a published tag is a reproducible source snapshot, not a production-readiness or third-party-certification claim. Older snapshots do not have a separate long-term maintenance commitment. Please report relevant vulnerabilities even if you find them in an older version.
The security and privacy model explains the configured control and observation boundaries. The trust bootstrap guide explains how callers establish trusted keys independently of an evidence packet.
Signature verification establishes integrity and authenticity relative to a trusted key. Business-outcome claims depend on the configured observation, its binding, and the covered action path. A passing verifier is not a guarantee that every Agent action is safe.