Security policy
Tell us privately. We will answer.
If you have found a way to make hermes-mordred leak, run open, or lie in its status output, that is the bug we most want to hear about. Do not open a public issue for it.
- Include
- Version, platform, reason code, and the smallest reproduction you have.
- Omit
- Your audit log, your keys, and anything belonging to a third party.
- Credit
- Given by name if you want it, withheld if you do not.
[TBD]Engineering to supply the mailbox address, PGP key, and hosted security.txt.
What happens after you send it.
Within 72h
A human acknowledges the report and says whether we can reproduce it.
Within 7 days
A severity assessment and a target date, or an explanation of why it is out of scope.
Within 90 days
A fix ships, or we tell you why it cannot and what we are doing instead.
Disclosure
Published in the changelog under SECURITY once a fixed release is out.
In scope
- Any path that gets key material out of the Enclave or TPM.
- Traffic leaving through an undeclared route.
- A guard bypass that puts a secret in a remote prompt.
- Plaintext reaching a gateway that should have seen ciphertext.
- A status output that reports a guarantee as met when it is not.
Out of scope
- Findings that require root or a compromised OS.
- Vulnerabilities in hermes-agent itself — report those upstream.
- Traffic-analysis observations already listed in the threat model.
- Scanner output with no demonstrated impact.
Supported versions
In alpha, only the latest release gets fixes. Backports start at 1.0.
| Version | Status | Security fixes |
|---|---|---|
| 0.1.0a17 | current | yes |
| ≤ 0.1.0a16 | superseded | no — upgrade |