Coldstar is security software, and it's open source so you can verify that claim rather than take it on faith. If you find a vulnerability, we want to hear from you — here's how the model works and how to report.
Email [email protected] with a description, reproduction steps, and impact. Please give us a reasonable window to fix before public disclosure.
We aim to acknowledge within 72 hours. We won't pursue legal action against good-faith research that respects user data and this policy.
Coldstar is beta software. An independent third-party security audit is planned ahead of the production release, covering the signing core and the agent-policy engine. Until it completes, treat Coldstar as beta: start with small amounts and verify addresses on the air-gapped device. Public findings and the audit report will be linked here when available.
In scope: the Coldstar CLI, the Seeker app, and this website and its APIs. We're especially interested in anything touching key handling, the signing path, or the air gap. Out of scope: findings that require a fully compromised host the user already controls, social-engineering of the user, or issues in third-party dependencies (report those upstream, and let us know so we can pin around them).