C3R's Verifier Firewall and Trusted Commit Gateway are security boundaries. Vulnerabilities that could bypass hard masks, substitute authority, suppress failed verification, commit an unapproved effect, leak protected state, or corrupt evidence-grade traces should be treated as high severity.
Please report suspected vulnerabilities privately to security@colomboai.com with:
- affected version or commit;
- minimal reproduction;
- expected and observed authority result;
- whether an external effect occurred;
- relevant trace identifiers with secrets removed.
Do not include credentials, private customer data, or active exploit details in a public issue.