Security

responsible disclosure · in force 2026-07-02

Aedelgard is a memory you own. Its whole value rests on trust, so we treat security reports as first-class work, not a compliance afterthought. The full policy also lives in the open engine at SECURITY.md.

Report privately, before public disclosure:

security@aedelgard.com

Want to encrypt? Send a first, contentless email and we'll exchange a key.

Include, where you can: what you found, how to reproduce it, the affected component (engine / cloud broker / desktop body), and its impact.

What to expect

Acknowledgement of your reportwithin 3 business days
Initial assessment + severitywithin 7 business days
Fix or mitigation planas soon as it's understood

We will keep you updated, credit you if you wish (or honour a request to stay anonymous), and we will not pursue good-faith researchers who follow this policy.

The honest trust boundary

We state this plainly on the architecture page and repeat it here because it is the truth your threat model should assume:

Especially wanted: tenant-isolation escapes, device-token forgery, vault-at-rest weaknesses, and anything that would let plaintext leave a user's machine when they run the local body. If a claim anywhere in the product contradicts our privacy statement, the claim is the bug — tell us.

Artifact integrity

Every desktop release publishes SHA256 checksums at aedelgard.com/checksums and on each GitHub release. Verify before you install.