SECURITY.md (796B)
1 # Security policy 2 3 ## Reporting 4 5 Use GitHub private vulnerability reporting when it is available. 6 7 Do not publish secret keys, nsec values, NIP-46 secrets, decrypted private 8 contracts, or exploitable operational details in a public issue. 9 10 ## Scope 11 12 Security-sensitive areas include: 13 14 - key generation and recovery; 15 - operating-system keyring custody; 16 - FFI compatibility; 17 - native library loading; 18 - database migrations and recovery; 19 - operation replay; 20 - relay transport; 21 - private Nostr events; 22 - package provenance; 23 - dependency policy. 24 25 ## Expectations 26 27 Reports should include: 28 29 - affected commit; 30 - affected platform; 31 - reproduction steps that do not expose real secrets; 32 - expected and observed behaviour; 33 - impact. 34 35 The project makes no production-readiness claim during the alpha phase.