Etminan is built for a demanding threat model — a fully root-compromised monitored host that must not be able to forge a "genuine" verdict or silently suppress an alarm. We take reports against that property, and against the code that enforces it, seriously. This page is our coordinated-disclosure policy: how to reach us, what's in scope, and what to expect.
Please do not open a public issue for a suspected vulnerability, and give us a reasonable opportunity to release a fix before any public disclosure.
[SECURITY].hkps://keys.openpgp.org and served here as
gpg-etminan-team.asc.etminan-agent,
etminan-verifier, the shared common crate, packaging/release
signing, or the website), the version or commit affected, steps to reproduce, the
impact, and a proof of concept if you have one.Etminan Team <team@etminan.dev>
Fingerprint: 7387 4214 090F 9137 862D 0AF1 E1E5 41B7 B424 36DF
We do not promise a fixed remediation SLA, but we do commit to the following.
The out-of-scope items below follow directly from the documented threat model, not from a wish to dodge reports.
etminan-agent and etminan-verifier binaries
and the shared common crate.Each release receives security updates for up to 12 months from its release date. At most one release is supported at a time: when a newer release supersedes it, security fixes move to the new release and you should upgrade to stay supported.
Etminan assumes the monitored host may already be fully compromised, and is built so that host cannot forge a genuine verdict or silently suppress an alarm — the evidence is anchored in a TPM the host's own root cannot rewrite and is verified off-box. See the architecture and the comparison with AIDE/Tripwire/Samhain for the full model. A report that breaks this property is the highest-severity class we handle.