| Version | Supported |
|---|---|
| 0.1.x | yes |
Email security reports privately to the maintainers via GitHub Security Advisories on this repository (preferred) or by opening a private security advisory.
Please include:
- AegisProof version / commit
- Steps to reproduce
- Impact (path escape, digest bypass, DoS, etc.)
We aim to acknowledge within 3 business days and coordinate fixes on a ~90-day disclosure window by default.
There is no paid bug bounty at this time.
A successful integrity check is not a claim of legal compliance, safety, or certification. See SPEC.md.