Skip to content

Security: ColomboAI-com/c3r

Security

SECURITY.md

Security policy

C3R's Verifier Firewall and Trusted Commit Gateway are security boundaries. Vulnerabilities that could bypass hard masks, substitute authority, suppress failed verification, commit an unapproved effect, leak protected state, or corrupt evidence-grade traces should be treated as high severity.

Please report suspected vulnerabilities privately to security@colomboai.com with:

  • affected version or commit;
  • minimal reproduction;
  • expected and observed authority result;
  • whether an external effect occurred;
  • relevant trace identifiers with secrets removed.

Do not include credentials, private customer data, or active exploit details in a public issue.

There aren't any published security advisories