
Security disclosure.
Acknowledgement within 3 business days.
Fix or disposition published with the next release notes.
Reporting
Send findings to security@vaultdb.ch. Include the engine version, a description, and steps to reproduce; a failing test against the crate is the fastest path to a fix. We acknowledge within three business days and keep you informed until disposition.
Safe harbour
Good-faith research against your own stores and your own builds of VaultDB is welcome. We will not pursue researchers who follow this page, avoid data that is not theirs, and give us reasonable time before publishing.
What we publish
The threat model and the documented edges (see Guarantees), the security-audit record — nine independent models, July 2026; every Critical and High closed with a regression test each — the FIPS provenance (AWS-LC-FIPS 2.0, CMVP #4816 / #4759), and the frozen at-rest conformance vectors, so anyone can check that a build has not changed the format.
What we do not do
We do not silently patch. A finding is either fixed with a test that fails against the previous code, or assessed and written up as an edge with its reasoning. Both are published.