Skip to content

Security: PAXECT-Interface/paxect-polyglot-plugin

Security

SECURITY.md

PAXECT logo

Security Policy — PAXECT Polyglot

Security is a first-class principle of the PAXECT Polyglot Plugin and the broader PAXECT ecosystem.
All modules — Core, AEAD Hybrid, Polyglot, SelfTune, and Link — are developed with deterministic design, zero telemetry, and full reproducibility in mind.


Supported Versions

Only the latest main branch and official tagged releases are actively supported and reviewed for security issues.
Older versions are provided as-is without any maintenance or guarantee.

Version Supported
main ✅ Active
1.x ⚠️ Best effort

Reporting a Vulnerability

If you discover a vulnerability or security risk, please report it privately and responsibly.

Contact options:

  • enterprise@[email protected] (preferred for enterprise or compliance disclosures)
  • [email protected] (general coordination)
  • GitHub: use Security → Advisories → Report a vulnerability

Do not create public Issues or Pull Requests for unresolved vulnerabilities.


Disclosure Process

  1. The report will be acknowledged within 72 hours.
  2. A maintainer will contact you for additional details or proof of concept, if required.
  3. A fix or mitigation will be developed privately.
  4. Once verified, a coordinated public advisory and changelog entry will be published.
  5. Researchers may be credited for responsible disclosure, if they wish.

Guidelines for Researchers

To ensure safe and lawful testing:

  • Do not test on production or live environments.
  • Avoid social engineering, spam, or denial-of-service attacks.
  • Keep findings confidential until an official patch or advisory is released.
  • Follow good-faith principles of coordinated disclosure.

Related Documents


© 2025 PAXECT Systems. All rights reserved.
For all responsible disclosure inquiries: [email protected]

There aren’t any published security advisories