Skip to content

Security policy

The full policy lives in SECURITY.md in the vaultkeepr-public repository. This page summarizes it.

Do not open a public GitHub issue for a security vulnerability. Report it privately:

  • GitHub Security Advisories (preferred): use the “Report a vulnerability” button on the Security tab of the repository.
  • Email: [email protected]

Include a description of the issue and its impact, steps to reproduce (a proof of concept if possible), and the affected packages and versions. The project acknowledges reports within 48 hours and aims to provide a fix or mitigation within 30 days, depending on severity. Coordinated disclosure is appreciated.

The policy covers the open-source packages and Solidity contracts: packages/core, packages/sync, packages/ipfs, packages/recovery, packages/premium, packages/wallet-messages, packages/smart-account, packages/cloud, packages/alias, packages/logger, packages/i18n, packages/ui, packages/sentry, packages/legacy, packages/ocr-native, and contracts/.

The web app, browser extension, iOS/Android apps, and the enterprise/API server are in a private repository and are out of scope for this public policy.

Finding typeSeverityTarget
Dependency (SCA)Critical / HighFix or mitigate within 7 days
Dependency (SCA)MediumWithin 30 days
Dependency (SCA)LowWithin 90 days, or accepted with written justification
SAST (CodeQL)New High/CriticalBlocks merge; triage within 7 days

Open findings that cannot be fixed upstream are documented in the accepted risk register in SECURITY.md and re-evaluated monthly.

Automated scan reports for the shipped clients and web app are published in the repository’s audits/ directory. These are tool-generated reports, not manual third-party code audits. Past reports include extension, iOS, and Android audits, VirusTotal scans, an MDN HTTP Observatory report for vaultkeepr.xyz, MobSF static analysis of the Android APK, and Maestro end-to-end runs. They are refreshed with each client release.

Client artifacts (Android APK, iOS IPA, browser extensions) are signed with minisign (Ed25519). The public key is committed in the repository as minisign.pub:

Terminal window
gh release download v0.2.0 -R VaultKeepR/vaultkeepr-public
curl -LO https://raw.githubusercontent.com/VaultKeepR/vaultkeepr-public/main/minisign.pub
minisign -Vm vaultkeepr-android-v0.2.0.apk -p minisign.pub
shasum -a 256 -c checksums.txt

Every release ships a checksums.txt with its own minisign signature. If signature verification fails, do not install the artifact and open a security advisory.

The @vaultkeepr/* npm packages are built by GitHub Actions from the repository and carry SLSA build provenance:

Terminal window
npm pack @vaultkeepr/core
gh attestation verify vaultkeepr-core-0.1.3.tgz --repo VaultKeepR/vaultkeepr-public

This attestation covers the npm SDK tarballs only. Application artifacts are built on the maintainer’s machine and covered by the minisign signature and the signed checksums; no CI build provenance is claimed for them.