Security policy and vulnerability disclosure
Last updated
How to report a vulnerability to INTYGA, what response times to expect, and the architectural invariants we hold ourselves to.
Reporting a vulnerability
If you find a vulnerability or a potential control failure in INTYGA, report it privately to security@intyga.com. Please do not open a public issue for an undisclosed vulnerability.
| Stage | Target |
|---|---|
| Initial acknowledgment | Within 24 hours |
| Triage and assessment | Within 72 hours |
| Remediation for high or critical severity | Within 7 business days |
We will keep you informed through remediation and will credit you publicly if you would like that. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosing.
Architectural invariants
These are enforced at the engine, database, and verifier levels, and are treated as non-negotiable in code review.
- No central secret for receipt attestation. Offline verification requires no INTYGA secret; relying parties recompute the canonical payload and verify the human's signature themselves.
- Per-action step-up. Mutating administrative and state-changing actions require a per-action passkey or security-key signature, not a session.
- Zero-knowledge policy relay. Our servers store only your organization's public key. Policy decryption happens client-side in the operator's browser.
- Multi-tenant isolation. Tenant queries run under enforced database row-level security with a non-owner application role.
- Privacy minimization. Push notifications contain opaque nonces only — never action descriptions, amounts, document names, or personal data.
Vulnerability management
Dependency auditing runs on every CI build. Critical security patches for dependencies and engine components are deployed within 24 hours of notification. Security-relevant events — credential registration, challenge creation, approvals, denials — emit immutable audit entries.