Security policy
The full policy lives in SECURITY.md in the vaultkeepr-public repository. This page summarizes it.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Do not open a public GitHub issue for a security vulnerability. Report it privately:
- GitHub Security Advisories (preferred): use the “Report a vulnerability” button on the Security tab of the repository.
- Email: [email protected]
Include a description of the issue and its impact, steps to reproduce (a proof of concept if possible), and the affected packages and versions. The project acknowledges reports within 48 hours and aims to provide a fix or mitigation within 30 days, depending on severity. Coordinated disclosure is appreciated.
The policy covers the open-source packages and Solidity contracts: packages/core, packages/sync, packages/ipfs, packages/recovery, packages/premium, packages/wallet-messages, packages/smart-account, packages/cloud, packages/alias, packages/logger, packages/i18n, packages/ui, packages/sentry, packages/legacy, packages/ocr-native, and contracts/.
The web app, browser extension, iOS/Android apps, and the enterprise/API server are in a private repository and are out of scope for this public policy.
Remediation targets
Section titled “Remediation targets”| Finding type | Severity | Target |
|---|---|---|
| Dependency (SCA) | Critical / High | Fix or mitigate within 7 days |
| Dependency (SCA) | Medium | Within 30 days |
| Dependency (SCA) | Low | Within 90 days, or accepted with written justification |
| SAST (CodeQL) | New High/Critical | Blocks merge; triage within 7 days |
Open findings that cannot be fixed upstream are documented in the accepted risk register in SECURITY.md and re-evaluated monthly.
Scan reports and audits
Section titled “Scan reports and audits”Automated scan reports for the shipped clients and web app are published in the repository’s audits/ directory. These are tool-generated reports, not manual third-party code audits. Past reports include extension, iOS, and Android audits, VirusTotal scans, an MDN HTTP Observatory report for vaultkeepr.xyz, MobSF static analysis of the Android APK, and Maestro end-to-end runs. They are refreshed with each client release.
Verifying a release
Section titled “Verifying a release”Client artifacts (Android APK, iOS IPA, browser extensions) are signed with minisign (Ed25519). The public key is committed in the repository as minisign.pub:
gh release download v0.2.0 -R VaultKeepR/vaultkeepr-publiccurl -LO https://raw.githubusercontent.com/VaultKeepR/vaultkeepr-public/main/minisign.pubminisign -Vm vaultkeepr-android-v0.2.0.apk -p minisign.pubshasum -a 256 -c checksums.txtEvery release ships a checksums.txt with its own minisign signature. If signature verification fails, do not install the artifact and open a security advisory.
The @vaultkeepr/* npm packages are built by GitHub Actions from the repository and carry SLSA build provenance:
npm pack @vaultkeepr/coregh attestation verify vaultkeepr-core-0.1.3.tgz --repo VaultKeepR/vaultkeepr-publicThis attestation covers the npm SDK tarballs only. Application artifacts are built on the maintainer’s machine and covered by the minisign signature and the signed checksums; no CI build provenance is claimed for them.