SECURITY ENFORCEMENT FRAMEWORKINDEX REF: VEX-SEC-2026

Vulnerability Reporting

We prioritize immediate mitigation of vulnerabilities. If you detect any technical issues inside our distribution channels, please report your findings to support@vexir.art.

OFFICIAL SECURITY POLICY RECORD

EN BINDINGS APPROVED

SECURITY POLICY

This document outlines the security policies, threat classifications, reporting procedures, and response commitments for this project.

VEX IR is committed to protecting both the integrity of the Tool and the safety of the systems on which it runs.

By VEX IR


1. SCOPE AND COPIES

Security evaluations and vulnerability reports are only valid for original releases obtained directly from the channels specified in TRUSTED.md.

VEX IR does not evaluate or take responsibility for Modified Versions, unofficial forks, or distributions made on third-party registries. If you are running a Modified Version, refer to that distribution's security policy.


2. SUPPORTED VERSIONS

Only the latest active release version of the Tool receives security updates and patches. Once a new version is released, older versions are considered end-of-life (EOL) and do not receive security evaluations or backported fixes.


3. REPORTING A VULNERABILITY

Do NOT open a public issue in ISSUE.md or any other public forum for suspected security vulnerabilities. Public exposure increases risk before a patch is prepared.

Submit all security vulnerability reports privately via the official contact email listed under Section 7 of the VECE ORIGIN LICENSE, or as otherwise directed in the trusted distribution channels.

Include the following information in your report:

  • A detailed description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce the issue, including a working
  • proof-of-concept (PoC) if possible.
  • The environment, version, and architecture under which the issue was
  • found.

4. RESPONSE TIME AND PATTERNS

Upon receiving a private security report:

  • VEX IR will acknowledge receipt of the report within 3 business days.
  • If verified, a patch or mitigation strategy will be developed.
  • The reporter will be kept updated periodically on the progress of the fix.
  • Security advisories and patched releases will be made available as
  • soon as practical, after which public disclosure can proceed.

5. CREDITS AND ATTRIBUTION

VEX IR respects and values the work of security researchers who report issues responsibly. With your permission, public credit will be given in release notes and change logs once the vulnerability has been patched and disclosed.


6. OUT OF SCOPE

The following are generally not considered valid security reports unless a credible, concrete impact is demonstrated:

  • Vulnerabilities that only affect outdated, unsupported versions.
  • Vulnerabilities that require unrealistic prerequisites, such as full
  • control of the user's machine.
  • Theoretical issues without a working proof of concept or clear
  • impact.
  • Vulnerabilities found in unofficial forks or unverified copies, as
  • described in Section 1.

7. PRIVACY DURING THE SECURITY PROCESS

All security communication must go through the channel described in Section 3. At no point during the reporting, review, or disclosure process should an attempt be made to identify, contact outside official channels, or expose the personal identity of VEX IR. This is treated as a serious violation under Section 7 of the VECE ORIGIN LICENSE, regardless of the validity or severity of the security report itself.


8. NO BOUNTY PROGRAM

This project does not currently operate a paid bug bounty program. Recognition for valid, responsibly disclosed reports is given through public credit, as described in Section 5, unless and until a formal bounty program is announced.

By VEX IR

Public Verification Keys

PGP PRIVATE SHIELD BLOCK

VERIFY REPOSITORY BUILD SIGNATURES WITH THE CORRESPONDING PUBLIC GPG KEYS:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.22 (GNU/Linux)

mQENBFH1x18BCADuR+b9mZ5B8u6uW8pB9qB4S0L6X+Z7WqTjJ/k+T8F9tO9D3p7j
N9A/W4h8Lq/Z3K2R3M8N7Jg1zXq8U9gWv6B9D/N8U7p8Y7K3m5W9e9y3P+n8gW7j
=fG3W
-----END PGP PUBLIC KEY BLOCK-----