SCCP v0.1 is research code and must not protect real secrets.
Please report protocol or implementation flaws through a private GitHub security advisory when available. Do not include production keys, personal data or third-party secrets in a report.
In scope: certificate binding, epoch/parent validation, transcript construction, AEAD misuse, signature validation, canonical encoding ambiguity, rollback/fork evidence and documentation that could cause unsafe deployment.
Out of scope: claims that the package is not production-ready; that limitation is explicit.