Security · Audits

Security
audits

Audit reporting belongs in the open: publish links to third-party reports when available, and keep day-to-day security work anchored to verifiable checks and a clear disclosure process.

Status
Pre-audit
CI
Continuous
Channel
Private disclosure
§ 01
Published today

What you can verify on this page

When third-party audit reports exist, they are linked here. If nothing is linked, treat the status as unpublished — not as an implied clean bill of health.

status · Not linked

Third-party audits

No third-party audit report is linked on this page at the moment. When audits are completed and approved for release, published reports will appear here with dates and scope.

channel · Private first

Security communication

Vulnerabilities should be reported privately. Fixes should ship before public discussion whenever possible. See the disclosure process for channels and response targets.

Disclosure process →

§ 02
Continuous verification

What this website repository enforces

A small set of repeatable checks. Other repositories may have additional gates — treat their CI workflows as the canonical source.

CheckCommand
Lintbun run lint
Linksbun run check:links
Doc samplesnode scripts/check-doc-samples.mjs
Buildbun run build
ScopeThis website repo
SamplesDoc snippets must stay executable
LinksInternal hrefs must resolve
Next

Prefer prevention over reaction?

Start with the threat model and primitive choices, then push edge cases into RFCs so verifier behavior stays explicit.