Skip to content

Security: XMECK-LAB/TRANSCRIPT

Security

SECURITY.md

Security Policy

TRANSCRIPT / KAVACH publishes public engineering previews and a KAVACH 2.0 software-reference implementation.

Supported public lines

Line Status Security posture
KAVACH 2.0 Current public software reference Active public engineering line
KAVACH 1.0 Historical engineering preview Historical Windows preview

Reporting a vulnerability

Do not post exploit details, credentials, private evidence, or sensitive reproduction material in a public issue.

When GitHub private vulnerability reporting is enabled for this repository, use the repository Security tab and choose Report a vulnerability.

If that private control is not available, open a public issue containing no technical vulnerability details and request a private security contact channel.

Current assurance boundary

The public KAVACH 2.0 line is a SOFTWARE_REFERENCE implementation.

This repository does not claim:

  • hardware-backed authority;
  • TPM / TEE / HSM assurance;
  • independent security certification;
  • formal verification;
  • vulnerability-free operation;
  • production security certification.

The KAVACH 1.0 Windows binary is an unsigned historical engineering preview; trusted publisher signing is not claimed.

See KAVACH/docs/CLAIM_BOUNDARY.md for the public claim boundary.

There aren't any published security advisories