Security
Report vulnerabilities and security-sensitive bugs to:
Please do not open public issues for unfixed security problems.
What to include
- Affected component (CLI, core, verify SDK language, extension, plugin)
- Version or commit if known
- Steps to reproduce
- Impact (integrity bypass, signature handling, path handling, etc.)
Scope notes
HashSeal provides content integrity for instruction files and trees (digests, optional GPG attestation via your git GPG setup). It does not claim to secure model behavior, prevent all supply-chain attacks, or replace code review.
Contacts
| Security | security@hashseal.ai |
| General | info@hashseal.ai |
Copyright (c) 2026 MonkeyKing.dev