RESPONSIBLE REPORTING

Security Reporting

Report vulnerabilities privately so they can be reproduced, contained, and documented without exposing users or protected systems.

PRIVATE CHANNELS

Repository-specific reporting

Website and observation gateway: fenrua-web private vulnerability report.

Kernel and P/N521 research artifacts: fenrua-kernel private vulnerability report.

Include the affected revision, exact reproduction steps, observed impact, and the minimum evidence required to validate the issue. Redact secrets and personal or client-confidential information.

ASSURANCE BOUNDARY

Public evidence is scoped

A passing public artifact, test, hash, workflow, or audit record is evidence only for its stated revision and scope. It is not a perpetual security guarantee, external certification, or attestation of protected runtime systems.

No response time, remediation deadline, bounty, safe-harbour term, or reward is promised by this page. Any such commitment must be separately published or agreed.