Skip to content

Security: ZoaGrad/sovereign-reliability-lab

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

Blackglass Continuum LLC prioritizes the integrity of sovereign and safety-critical infrastructure.

If you discover a vulnerability in the Phase Controller logic, audit pipeline, or entropy injection layer:

  1. Do NOT open a public issue.
  2. Email: colemanwillis01@gmail.com
  3. Reports follow Coordinated Vulnerability Disclosure (CVD) practices aligned with ISO/IEC 29147.

We acknowledge reports within 72 hours and provide remediation timelines where applicable.

Supply Chain Integrity

  • All releases are cryptographically signed.
  • Do not trust artifacts that fail signature verification.
  • Provenance metadata and SBOMs are published when applicable.
  • Build pipelines are version-locked and reproducible.

Unauthorized redistribution or tampering is prohibited.

There aren't any published security advisories