Security and responsible disclosure
Report vulnerabilities privately to security@emabled.com.
Scope
Reports may cover the XCIM protocol design, public web properties, reference-network components when released, proof verification, recipient privacy, issuer impersonation, key lifecycle and implementation behavior that could produce an incorrect positive result.
Reporting expectations
- Include the affected component, impact and reproducible steps.
- Do not include live recipient data or access data beyond what is necessary to demonstrate impact.
- Allow reasonable time for coordinated remediation before public disclosure.
- English and Spanish reports are supported.
Response and encryption
Target acknowledgement is five business days. A dedicated PGP key and counsel-reviewed safe-harbor statement are not yet published; this is an explicit pre-launch limitation. Sensitive reports should request an encrypted follow-up channel before sending secrets.
Machine-readable policy: /.well-known/security.txt.