szl-formulas / SECURITY.md
betterwithage's picture
Publish szl-formulas: honest stdlib-only offline replay kernel (14/14 & 13/13 trio)
59baf06 verified
|
Raw
History Blame Contribute Delete
1.83 kB

Security Policy

Reporting a Vulnerability

Do NOT open a public issue for security vulnerabilities.

Please report security vulnerabilities via email to security@szlholdings.com with:

  1. Description of the vulnerability
  2. Steps to reproduce
  3. Potential impact assessment
  4. Any suggested mitigations

Response SLA

Severity Initial Response Resolution Target
Critical 24 hours 7 days
High 48 hours 30 days
Medium 5 business days 90 days
Low 10 business days 180 days

We follow a 90-day responsible disclosure policy.

Scope notes for this artifact

  • No trained weights. This repository ships pure-Python, stdlib-only code — there is no .safetensors / .bin / .pt / .gguf weight artifact to poison or exfiltrate.
  • Offline by construction. The formulas are pure and no-I/O; the governed-loop composer performs no network access. Inputs are validated — bad weights, non-probability distributions, or k > n raise ValueError rather than returning a coerced answer.
  • Honest proof surface. PROOF_STATUS is mirrored verbatim from the canonical dataset; the locked-proven canonical set is fixed at exactly 8 and never inflated. A PROVEN(...) obligation tag is never upgraded into a locked-proven claim. Λ uniqueness stays Conjecture 1 (open).

Supply-Chain Security

  • DCO required — all commits carry Signed-off-by: trailers per Linux Foundation DCO
  • SLSA Build Level 1 — honest; not L2/L3

Contact

This policy follows the OpenSSF Vulnerability Disclosure Guide.