Skip to content

Security: ideatrino/halcyon

Security

SECURITY.md

Security Policy

Status

HALCYON is a reference implementation intended to demonstrate and prototype a partitioned-trust architecture. It has not undergone an independent security audit. Do not deploy it as-is to protect production systems without your own review and threat modeling. See SPEC.md §9 for known residual risks and §0 for the threat model it is scoped to.

Reporting a vulnerability

Please report suspected vulnerabilities privately rather than opening a public issue. Email: ideatrino@proton.me (replace before publishing).

Include, where possible:

  • a description of the issue and the layer/module affected,
  • steps or a minimal script to reproduce,
  • the impact you believe it has.

You can expect an acknowledgement within a few days. Coordinated disclosure is appreciated; we will credit reporters who wish to be named.

Scope

In scope: the control layer (Layer A / taint + checker + interpreter), the certified screen (Layer C), the DP accountant (Layer B), the integrity primitives (Layer D), and the ensemble (Layer E). Out of scope: the correctness/behavior of any third-party model you plug into the backends, and the security of the machine running the code.

There aren't any published security advisories