Security
Self-hosted. Air-gap works.
No phone-home required for the product to function. Releases are signed. Report vulnerabilities to [email protected].
Disclosure
Email [email protected]. We do not run a public bug bounty. Please include the version string and a reproduction that does not require production customer data.
Canonical file: /.well-known/security.txt.
Product posture
- Runs on your hosts. Air-gap capable.
- Entitlement verification is local (Ed25519 public key in the binary).
- Optional signed telemetry later; not required.
- Signed release artifacts and SHA256SUMS when binaries ship.
Supported versions
| Release | Status | Notes |
|---|---|---|
| — | None published | This table will list supported lines when v1 ships. |