Network security and responsible disclosure
Report vulnerabilities privately to security@emabled.com.
Scope
Before launch, scope includes these web properties and any explicitly published preview artifacts. After components launch it will expand to registry integrity, key lifecycle, roots and proofs, state freshness, anchors, mirrors and resolver behavior.
Expectations
Provide reproducible detail, avoid live recipient data and allow coordinated remediation. Target acknowledgement is five business days. English and Spanish reports are supported.
Known limitations
No production network is active. A dedicated PGP key and counsel-reviewed safe-harbor statement are not yet published. Request an encrypted follow-up channel before transmitting secrets.
Machine-readable policy: /.well-known/security.txt.