Eltanin implements security-sensitive local authorization and device enforcement. Please report vulnerabilities responsibly.
Do not open a public GitHub issue for a security vulnerability.
Instead, use GitHub's private vulnerability reporting for this repository (Security tab → "Report a vulnerability"), or contact the maintainers directly through the Horonom organization.
Include:
- affected version/commit;
- a description of the vulnerability and its impact;
- reproduction steps or a proof of concept, if available.
MVP 1.0 supported threat boundary is documented in
docs/product/SECURITY_MODEL.md. Reports
about explicitly out-of-scope platforms (Windows/macOS, AMD/Intel) or
explicitly stated non-goals are still welcome but tracked as future work,
not MVP 1.0 security incidents.
We aim to acknowledge reports within 5 business days. This is an early-stage MVP without a formal SLA.