This is the default security policy for repositories in the RegEngine organization.
Report vulnerabilities privately to legal@regengine.co.
Do not open public issues for security reports. Public disclosure before a fix ships puts users of the affected surfaces at risk; we will acknowledge private reports and coordinate disclosure.
RegEngine is pre-production software with no production customer data. The public proof surfaces are in scope for integrity bugs:
- regengine.co/proof — synthetic evidence bundles and exports.
- regengine.co/verify — public bundle verification.
A report that shows a way to make the verifier attest to tampered or fabricated evidence, or to break the hash-chain integrity guarantees of a published bundle, is exactly what this policy exists for.