Security scope

Authority Graph makes authorization decisions, but V0 has not completed an independent external human security audit.

Internal adversarial review

Théo Adam conducted an internal adversarial review. It identified four implementation gaps that were corrected and retained as regression tests. This work is not an independent external security audit.

Review targets

Threat-model validity, invariants, confused deputy behavior, delegation laundering, revocation, approval replay, temporal consistency, budget accounting, fail-closed behavior and algorithmic denial of service.

Responsible disclosure

Send sensitive reports through the private channel below. Do not include secrets or personal data in a public issue.

Report privately →

View repository security status →