Security
Reporting a vulnerability
Use GitHub private vulnerability reporting on sealedrun/sealedrun or write to . We acknowledge reports within 3 business days and publish a fix and advisory before disclosing details. Machine-readable contact: /.well-known/security.txt.
Current status
- No SOC 2 or ISO 27001 audit is underway. There is nothing hosted to audit yet.
- The cryptographic design has not had an independent third-party review.
- Releases are built by GitHub Actions and published to PyPI and npm with OIDC trusted publishing and provenance attestations.
- The verifier and the record format are open source under Apache-2.0 and ship with conformance test vectors in the repository.
Design
The threat model, what a bundle proves and does not prove, key compromise handling and deployment requirements for strong claims are documented in the trust model and the specification.