generated: '2026-09-19' method: searched probe: true source: https://github.com/Vortx-AI/emem/blob/main/SECURITY.md sources: - well-known/emem-dev-security.txt (https://emem.dev/.well-known/security.txt, 200, Expires 2027-09-20T01:46:26Z) - https://github.com/Vortx-AI/emem/blob/main/SECURITY.md (last updated 2026-08-24; also served at https://emem.dev/security, 200) - https://emem.dev/support policy: - https://github.com/Vortx-AI/emem/blob/main/SECURITY.md - https://emem.dev/security contact: - https://github.com/Vortx-AI/emem/security/advisories/new - mailto:avijeet@vortx.ai acknowledgments: https://github.com/Vortx-AI/emem/security/advisories canonical: https://emem.dev/.well-known/security.txt preferred_languages: [en] encryption: none - deliberately omitted; the only published key is an ed25519 signing key, which cannot encrypt (SECURITY.md explains the omission) program: type: coordinated vulnerability disclosure (no bug bounty, no HackerOne/Bugcrowd/Intigriti program found) acknowledgement: within 72 hours disclosure_timeline: 90 days from initial report to public fix + advisory; embargo shortened for non-controversial fixes or extended by agreement credit: in release notes, with permission safe_harbor: >- Stated - no legal action or law-enforcement referral against good-faith researchers who test only what they own or the public instance at reasonable rate, avoid others' data, allow remediation time and do not exfiltrate more than needed; "Activity consistent with this policy is authorised." scope: - emem responder (emem-server and the crates in the repo) - the emem protocol (signatures, merkle log, content addressing) - default-build data fetch paths (vsicurl Range reads, Nominatim geocoder) - the hosted instance https://emem.dev (and the hf.space mirror) out_of_scope: - third-party MCP / IDE clients - operator-registered upstream connectors not in the default build - cargo dependency bugs (report upstream) - upstream open-data providers (Open-Meteo, MET Norway, Copernicus DEM, JRC GSW, Hansen GFC, ESA WorldCover, OSM/Overture, NASA/USGS ...) supported_versions: 2.4.x current; <= 2.3.x unsupported (the hosted responder runs the tip of main) hardening_published: tls: rustls 1.2/1.3, modern ciphers, Let's Encrypt hsts: max-age=31536000; includeSubDomains; preload (observed live) csp: default-src 'self' with hash-based script-src/style-src, no analytics origin (observed live) other_headers: [X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CSP frame-ancestors/base-uri/form-action] body_cap: 16 MiB on POST (413) request_timeout: 40 s (504) per_ip_rate_limit: 600 req/min sustained, 120 burst, Retry-After 1 identity: ed25519 secret stored mode 0600, never logged unsafe_code: forbidden in emem-api-rest cryptographic_invariants: >- Five invariants the provider commits to patch immediately if broken - canonical CBOR CIDs identical across parties; order-stable merkle roots; receipts verify offline against the embedded responder key; the append-only merkle log replays bit-for-bit; the identity secret never appears in stdout/journal. evidence: - source: well-known/emem-dev-security.txt kind: security.txt (RFC 9116, harvested 2026-09-19) http_status: 200 - source: https://emem.dev/security kind: security policy page (markdown, same text as SECURITY.md) http_status: 200 - source: https://raw.githubusercontent.com/Vortx-AI/emem/main/SECURITY.md http_status: 200