Skip to content

Security: BosleySystems/Refusal-Proof-Demo

Security

SECURITY.md

Security Policy

Scope

This project is security-sensitive because it demonstrates governed execution, refusal-proof outcomes, receipt verification, impossibility artifacts, and append-only settlement verification.

Supported Versions

Only tagged releases are considered supported for coordinated disclosure.

Reporting a Vulnerability

Please report vulnerabilities privately.

Do not open public issues for:

  • unauthorized execution without admissibility
  • forged ALLOW outcomes
  • bypass of REFUSE or DEFER outcomes
  • token replay or substitution
  • receipt verification bypass
  • canonicalization mismatch
  • settlement tampering
  • replay inconsistencies

Please include:

  • affected version or commit
  • reproduction steps
  • expected behavior
  • observed behavior
  • impact
  • whether unauthorized execution or forged verification is possible

Severity Priorities

Highest severity:

  • execution without admissibility
  • forged or unverifiable receipts
  • bypass of governed refusal/defer behavior
  • broken settlement-chain integrity

Safe Harbor

Good-faith research and responsible disclosure are welcome.

There aren't any published security advisories