Skip to content

Security: Superlapie/Tortoise

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
0.1.x-alpha Development only — not production

Reporting a vulnerability

Please report security issues through GitHub private vulnerability reporting for this repository.

Do not publicly disclose privilege escalation or broker bypass issues before maintainers can address them.

Scope

High-priority areas:

  • Elevated broker and IPC
  • Driver installation paths
  • Signature verification
  • Update source providers
  • Recovery and rollback
  • Firmware policy enforcement

Safe harbor

Good-faith security research that avoids privacy violations, data destruction, and service disruption is appreciated. Do not test mutation features on production machines.

There aren't any published security advisories