Microtoll Engine pre-1.0 · the locks, pre-built

Security policy

Microtoll Engine is security software: sign-in, key handling, access control and revocation for end-to-end-encrypted apps. If you have found a weakness in it, thank you for reading this first.

Reporting

What to expect

Scope

In scope: the packages under packages/ (crypto-core, identity, access, mailbox, blind-store, mcp), the reference deployment under deploy/, the examples, and the documents that describe what they protect (THREATMODEL.md and each package's FORMATS.md). A gap between what the threat model claims and what the code does is in scope even if nothing is "exploited".

Out of scope: applications built on the engine (report to their owners), the docs site's hosting, and the limits the threat model already states (THREATMODEL.md §2: traffic shape, a compromised device, script injection into a page that holds keys).

Verifying a release

Release tags are signed with the maintainer's key; the public key is published here when the first release is made, and every published package carries npm provenance linking it to the tagged commit and the workflow that built it.