SealedRun

Security

Reporting a vulnerability

Use GitHub private vulnerability reporting on sealedrun/sealedrun or write to . We acknowledge reports within 3 business days and publish a fix and advisory before disclosing details. Machine-readable contact: /.well-known/security.txt.

Current status

  • No SOC 2 or ISO 27001 audit is underway. There is nothing hosted to audit yet.
  • The cryptographic design has not had an independent third-party review.
  • Releases are built by GitHub Actions and published to PyPI and npm with OIDC trusted publishing and provenance attestations.
  • The verifier and the record format are open source under Apache-2.0 and ship with conformance test vectors in the repository.

Design

The threat model, what a bundle proves and does not prove, key compromise handling and deployment requirements for strong claims are documented in the trust model and the specification.