Security and responsible disclosure

Report vulnerabilities privately to security@emabled.com.

Scope

Reports may cover the XCIM protocol design, public web properties, reference-network components when released, proof verification, recipient privacy, issuer impersonation, key lifecycle and implementation behavior that could produce an incorrect positive result.

Reporting expectations

Response and encryption

Target acknowledgement is five business days. A dedicated PGP key and counsel-reviewed safe-harbor statement are not yet published; this is an explicit pre-launch limitation. Sensitive reports should request an encrypted follow-up channel before sending secrets.

Machine-readable policy: /.well-known/security.txt.