Skip to content

Security: PAXECT-Interface/paxect-aead-hybrid-plugin

Security

SECURITY.md

PAXECT logo

Security Policy — PAXECT AEAD Hybrid Plugin

Supported Versions

Only the latest main branch and tagged releases are actively supported and reviewed for security issues.
Older versions are provided as-is without any security guarantee.

Version Supported
main ✅ Active
1.x ⚠️ Limited (best effort)

Reporting a Vulnerability

If you discover a security vulnerability, please report it privately and responsibly.

Contact options:

Do not create public Issues or Pull Requests for unresolved vulnerabilities.


Disclosure Process

  1. The report will be acknowledged within 72 hours.
  2. A maintainer will contact you for additional details or proof of concept (if needed).
  3. A fix or mitigation will be developed privately.
  4. Once resolved, a coordinated public advisory and changelog entry will be published.
  5. Researchers may be credited for responsible disclosure, if they wish.

Guidelines for Researchers

To ensure safe and lawful testing:

  • Do not test on production or live environments.
  • Avoid social engineering, spam, or denial-of-service attacks.
  • Keep findings confidential until an official patch or advisory is released.
  • Follow good-faith principles of coordinated disclosure.

Related Documents


© 2025 PAXECT Systems. All rights reserved.
For all responsible disclosure inquiries: 📧 PAXECT-Team@outlook.com

There aren't any published security advisories