avp

Alt Vault Protocol, an open zero-knowledge spec for sharing alts across clients.

Security policy

AVP is a protocol specification, so “security issues” here mean weaknesses in the design or in the machine-readable artifacts that could lead implementers to build something insecure. Examples:

Vulnerabilities in a specific client, server, or library that implements AVP belong to that project, not here. Please report those to the relevant project.

THREATMODEL.md describes what AVP defends against, what it does not, and the known residual risks. A report that sharpens or breaks part of that model is exactly what is most useful here.

Reporting

Please report security issues privately, not in a public issue or pull request.

Use GitHub’s private vulnerability reporting on this repository: open the Security tab and choose Report a vulnerability. That opens a private advisory visible only to you and the maintainers.

Include, as far as you can:

What to expect

This is a community project, so responses are best effort. We aim to acknowledge a report within a few days, agree on impact and a fix, and coordinate disclosure with you. Please give us reasonable time to publish a corrected version before disclosing publicly. Credit is given to reporters who want it.

Scope notes