The cryptography behind this project has not been independently reviewed. ATSMS is a proof of concept; external cryptographic review is a gating requirement before any of it carries real traffic, and it has not happened yet. Do not use this to protect anything that matters.
The full policy, the list of known issues, and the brief we would hand a security reviewer live with the
protocol, in the atsms repository.
Please report privately rather than opening a public issue, using GitHub's private vulnerability reporting on this repository (Security → Report a vulnerability). Tell us what you found, how to reproduce it, and the impact you think it has. We will credit you in the fix unless you would rather we did not.