Skip to content

Security and disclosure

Email security@protocolward.ai. Please do not open a public GitHub issue for security problems.

Helpful details to include:

  • the version (ward version) or the commit you tested
  • your config, with secrets and decoy names removed
  • steps to reproduce, and what you expected compared with what happened

We do not publish a PGP key yet. If you need an encrypted channel, say so in a first short message and we will set one up.

We follow coordinated disclosure: a window of 90 days from your first report. If a fix needs more coordination, we agree an extension with you case by case. With your permission, we credit you publicly once the fix ships.

In scope:

  • the code in the Protocol Ward repository
  • official release artifacts
  • update-bundle verification (ward update verify)
  • this website, including the protocolward.ai/ward Go import path

Out of scope:

  • third-party blocklists that Ward can load (please report those upstream)
  • bugs in dependencies that cannot be exploited through Ward (still welcome, but please go upstream first)

Machine-readable contact details are at /.well-known/security.txt.

This site loads no third-party scripts, fonts or analytics.