STRATAM io

Security

Report vulnerabilities privately. Do not open public issues for security findings.

Preferred contact: security@stratam.io (mailbox live).

Include: version/commit, minimal reproduction, impact, and whether the issue is an in-process library boundary vs deployment (IdP/KMS/backups).

For the model assessors care about (provenance, write path, forget honesty): Security model · Privacy (AU).

Lab defaults are not protective. See SECURITY.md in the repository.