Security
Security
Please report privately rather than in a public issue. We publish our own known-issues list and the brief we would
hand a reviewer, because a reader who finds the limit themselves trusts the next claim less.
Reporting a vulnerability
For anything in an ATSMS repository, use GitHub's private vulnerability reporting on that repository (Security → Report a vulnerability); the atsms SECURITY.md has the details and the scope. For this website, or anything that does not fit a repository, write to [email protected] with "Security" in the subject line. We acknowledge reports within five business days.
What we already know
- KNOWN-ISSUES.md
- review-scope.md, the brief we would hand an external reviewer
- The limitations section of the protocol overview
Review status
The cryptography has not had an independent security review. It is a gating requirement before the protocol carries traffic that matters, and this page will name the reviewer and their findings, including anything still open, when it has happened.