Skip to content

Security: galipeli/aegis-risk-resolution-kit

Security

SECURITY.md

Security Policy

Project status

Aegis is a Seed-stage concept and local synthetic/mock validation artifact. It is not deployed, does not hold funds and does not include live Alpend or OneSwap credentials/interfaces.

Reporting a vulnerability

Please report vulnerabilities privately to the repository owner through GitHub's private vulnerability reporting feature when enabled. Do not include private keys, wallet seeds, credentials or sensitive borrower data in an issue.

Include:

  • affected commit/file;
  • minimal reproduction;
  • security impact within the documented mock boundary;
  • suggested mitigation if known.

In scope

  • fail-open simulator paths;
  • arithmetic/state mutation errors;
  • Daml authorization or direct-create invariant bypass;
  • lifecycle races and replay within implemented contracts;
  • release packaging that leaks secrets or contradicts claim boundaries;
  • misleading evidence generation.

Documented limitations—not vulnerabilities by themselves

  • no official/live Alpend integration;
  • no authenticated OneSwap receipt adapter;
  • no real-capital deployment;
  • no full Python–Daml economic parity;
  • the synthetic constant-product venue model.

A vulnerability may still exist if the code falsely claims or behaves as though one of these limitations were solved.

Security principles

  • fail closed on missing, malformed, stale, future or unknown evidence;
  • preserve canonical protocol authority;
  • separate projected from realized state;
  • require multi-party authorization for lifecycle evidence;
  • bind policy/state provenance;
  • never treat ambiguous execution as terminal success;
  • publish bounded evidence rather than broad assurances.

There aren't any published security advisories