The full security policy — disclosure path, threat model, cryptography
in use, trust assumptions, and known limitations — lives in
docs/security.md.
To report a vulnerability:
- Do not open a public GitHub issue.
- Email the maintainer (see the
authorsfield of the workspaceCargo.toml) with the subject prefix[execlaw security]. - If you don't get an acknowledgement within 72 hours, escalate via GitHub's private Security Advisory flow on this repository's Security tab.
Expected timeline: 72 h ack, 1 week severity assessment, up to 90 d coordinated disclosure for High/Critical issues.
There is no bug bounty.