Security and disclosure
Report a vulnerability
Section titled “Report a vulnerability”Email security@protocolward.ai. Please do not open a public GitHub issue for security problems.
Helpful details to include:
- the version (
ward version) or the commit you tested - your config, with secrets and decoy names removed
- steps to reproduce, and what you expected compared with what happened
We do not publish a PGP key yet. If you need an encrypted channel, say so in a first short message and we will set one up.
What happens next
Section titled “What happens next”We follow coordinated disclosure: a window of 90 days from your first report. If a fix needs more coordination, we agree an extension with you case by case. With your permission, we credit you publicly once the fix ships.
In scope:
- the code in the Protocol Ward repository
- official release artifacts
- update-bundle verification (
ward update verify) - this website, including the
protocolward.ai/wardGo import path
Out of scope:
- third-party blocklists that Ward can load (please report those upstream)
- bugs in dependencies that cannot be exploited through Ward (still welcome, but please go upstream first)
Machine-readable contact details are at /.well-known/security.txt.
This site
Section titled “This site”This site loads no third-party scripts, fonts or analytics.