Security and responsible disclosure
Report a concern with care.
A reporting path for security, proof-integrity, and reproducibility concerns.
Sensitive findings.
Do not publish private keys, seed phrases, API credentials, personal records, or exploitable secret material in issues. Email ceo@keyai.org with a non-sensitive summary first, so the maintainer can arrange an appropriate private channel. You may also use GitHub's private vulnerability reporting feature if it is enabled for the repository.
This page does not claim that private vulnerability reporting is enabled or promise a response deadline or bounty.
Proof and reproducibility issues.
For non-sensitive issues, include the source commit, a minimal reproduction, the exact theorem and assumptions, toolchain, observed output, and expected behavior. Explain whether the concern affects scope, proof trust, a verifier, generated metadata, or automation.
Research boundaries.
The repository contains research software, not a production wallet, signing service, or audited cryptographic implementation. Formalized algebra at a stated scope is not a security proof for a deployed protocol.
Reporting a concern does not authorize testing third-party systems or accessing data or funds. Follow the controlled research scope.