Currently, the main branch is actively supported with security updates.
Security is a top priority for Rayos Relay. Since this backend handles passkey orchestration and social recovery, we take all vulnerabilities very seriously.
Please DO NOT report security vulnerabilities through public GitHub issues.
Instead, please report them by emailing security@rayos.dev (or the project maintainer's email). You should receive a response within 48 hours.
- A description of the vulnerability.
- Steps to reproduce.
- Potential impact.
- We will acknowledge receipt of your vulnerability report.
- We will investigate and confirm the vulnerability.
- We will draft a patch and release a security advisory.
To understand our security model and how user keys are protected (hint: they never touch the relay), please read docs/TRUST.md.