Skip to content

Security: horonomy/eltanin

SECURITY.md

Security Policy

Eltanin implements security-sensitive local authorization and device enforcement. Please report vulnerabilities responsibly.

Reporting a vulnerability

Do not open a public GitHub issue for a security vulnerability.

Instead, use GitHub's private vulnerability reporting for this repository (Security tab → "Report a vulnerability"), or contact the maintainers directly through the Horonom organization.

Include:

  • affected version/commit;
  • a description of the vulnerability and its impact;
  • reproduction steps or a proof of concept, if available.

Scope

MVP 1.0 supported threat boundary is documented in docs/product/SECURITY_MODEL.md. Reports about explicitly out-of-scope platforms (Windows/macOS, AMD/Intel) or explicitly stated non-goals are still welcome but tracked as future work, not MVP 1.0 security incidents.

Response

We aim to acknowledge reports within 5 business days. This is an early-stage MVP without a formal SLA.

There aren't any published security advisories