Do NOT open a public GitHub issue for security vulnerabilities.
Email security@cuecrux.com with:
- Description of the vulnerability
- Steps to reproduce
- Affected versions
- Impact assessment (your best estimate)
| Stage | Target |
|---|---|
| Acknowledgment | 48 hours |
| Assessment | 7 days |
| Fix release | 30 days |
CROWN receipt integrity bugs are treated as critical severity regardless of exploitability.
| In scope | Out of scope |
|---|---|
corecruxd daemon |
VaultCrux hosted platform |
corecruxctl CLI |
Third-party dependencies (report upstream) |
All corecrux-* crates |
Social engineering |
| CROWN receipt generation/verification | |
| BLAKE3 chain integrity | |
| Tenant isolation |
| Version | Supported |
|---|---|
| 0.5.x | Current release |
| < 0.5 | Best effort |
Accepted reports receive credit in CHANGELOG.md and any published security advisory.
For sensitive reports, request our PGP key via security@cuecrux.com.