Disclosure & Contact
Reporting a security issue
Konstruct does not operate a security inbox. Use GitHub's private vulnerability reporting on any of the relevant repositories — your report will be visible only to maintainers until a fix is published.
- construct-core — cryptographic core
- construct-ios — iOS / macOS client
- construct-server — server-side
- construct-veil — anti-censorship transport
- construct-engine — QUIC engine
- construct-protocol — issues with this specification
The canonical disclosure metadata file (RFC 9116) is at konstruct.cc/.well-known/security.txt.
Scope
Cryptographic, transport, or implementation issues in any of the public repositories listed above are in scope.
Server infrastructure issues (denial-of-service, mis-configuration of the single deployment server) are out of scope while the project is in single-server alpha — the whole network depends on one trusted operator today, and infrastructure hardening is part of the federation roadmap rather than something a disclosure can usefully fix.
Project updates
Project updates and ad-hoc technical posts are at @maxeliseyev on X.