Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Disclosure & Contact

Reporting a security issue

Konstruct does not operate a security inbox. Use GitHub's private vulnerability reporting on any of the relevant repositories — your report will be visible only to maintainers until a fix is published.

The canonical disclosure metadata file (RFC 9116) is at konstruct.cc/.well-known/security.txt.

Scope

Cryptographic, transport, or implementation issues in any of the public repositories listed above are in scope.

Server infrastructure issues (denial-of-service, mis-configuration of the single deployment server) are out of scope while the project is in single-server alpha — the whole network depends on one trusted operator today, and infrastructure hardening is part of the federation roadmap rather than something a disclosure can usefully fix.

Project updates

Project updates and ad-hoc technical posts are at @maxeliseyev on X.