Security & Responsible Disclosure

Stella Ops Suite is designed for verifiable release governance:

  • Releases are CosignContainer signing tool from Sigstore project for signing and verifying container images and artifacts-signed
  • Evidence exports are DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures-attested
  • Policies and decisions can be replayed deterministically for audit

Vendor security review

Doing vendor due diligence? The review page collects the public verification artifacts and documentation, and lists what is not yet published.

Report a vulnerability

Email: security@stella-ops.org

PGP fingerprint: 4976 7614 4BBA 5DDB E2EA B5B8 5C1E CABB C9F3 1EA6

That fingerprint belongs to the Stella Ops release-signing key — its user ID is Stella Ops Release Signing <release@stella-ops.org>. The same key currently signs security correspondence, so a signed message from us verifies against it.

A dedicated security-contact key, separate from release signing, and a published key-rotation policy are planned. Neither exists yet.

Please include:

  • Impact + affected component/version
  • Reproduction steps or PoC
  • Relevant logs/screenshots
  • Your preferred disclosure timeline

We acknowledge within 72 hours and keep you informed until a fix is published.

Verify what you run

Verification commands for container images and Offline Kit artifacts, together with the Cosign and PGP keys, are maintained at /keys/.

Safeguards in service

  • Release integrity: CosignContainer signing tool from Sigstore project for signing and verifying container images and artifacts signatures + DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures bundles referencing the exact Git tag
  • Evidence chain: Decision Capsules are signed and replayable (see /evidence/)
  • Container hardening: deployment guidance in the Security Hardening Guide
  • Air-gap parity: Offline Kit (see /sovereign/)

No mandatory telemetry

No analytics, trackers, pixels, or third-party JS in the web UI. Product telemetry is disabled by default and strictly opt-in.

Privacy details: /privacy/