Skip to content

Security: sovereignengine/sovereign-engine-final

Security

SECURITY.md

Security Policy - Sovereign Engine Core

Version Audit Ready Runtime Security Compliance


Supported Versions

The Sovereign Engine follows a "Rolling Release" model under the Sovereign Protocol. Only the latest version is supported for security updates.

Version Supported
8.x.x
< 8.0.0

Reporting a Vulnerability

DO NOT OPEN A PUBLIC ISSUE FOR SECURITY VULNERABILITIES.

As an autonomous bunker environment, we take security with extreme seriousness. If you find a vulnerability that could compromise the Sovereign Engine or its Agentic integrity:

  1. Encrypt your report: Use the project's PGP key (available in ./security_guards/KEYS).
  2. Submit via Sentinel: Send the encrypted report to security@sovereign-engine.com.
  3. Wait for Audit: Our S.L.A.V.K.O. Overseer will verify the claim against the AuditChain within 24 hours.

Operational Security (OPSEC)

  • All security reports are logged in an immutable WORM (Write-Once-Read-Many) storage.
  • Falsely reporting vulnerabilities to "shadow" the system will result in an immediate ZERO_TRUST_VIOLATION and IP blacklist.

Compliance

This project aims for full compliance with the EU AI Act, NIS2, and Gaia-X requirements for sovereign cloud environments.

There aren’t any published security advisories