Security scope
Authority Graph makes authorization decisions, but V0 has not completed an independent external human security audit.
Internal adversarial review
Théo Adam conducted an internal adversarial review. It identified four implementation gaps that were corrected and retained as regression tests. This work is not an independent external security audit.
Review targets
Threat-model validity, invariants, confused deputy behavior, delegation laundering, revocation, approval replay, temporal consistency, budget accounting, fail-closed behavior and algorithmic denial of service.
Responsible disclosure
Send sensitive reports through the private channel below. Do not include secrets or personal data in a public issue.
Report privately →