Skip to content

Security: Rayos-Org/relay-backend

Security

docs/SECURITY.md

Security Policy

Supported Versions

Currently, the main branch is actively supported with security updates.

Reporting a Vulnerability

Security is a top priority for Rayos Relay. Since this backend handles passkey orchestration and social recovery, we take all vulnerabilities very seriously.

Please DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them by emailing security@rayos.dev (or the project maintainer's email). You should receive a response within 48 hours.

What to include

  • A description of the vulnerability.
  • Steps to reproduce.
  • Potential impact.

Our Process

  1. We will acknowledge receipt of your vulnerability report.
  2. We will investigate and confirm the vulnerability.
  3. We will draft a patch and release a security advisory.

Trust Model

To understand our security model and how user keys are protected (hint: they never touch the relay), please read docs/TRUST.md.

There aren't any published security advisories