How do I report a vulnerability to AffixIO?
Email hello@affix-io.com and use https://www.affix-io.com/security/. RFC 9116 contact details are in https://www.affix-io.com/.well-known/security.txt.
Security
AffixIO publishes a machine-readable security.txt and a clear path for responsible disclosure.
If you find a vulnerability in AffixIO services or published SDKs, email hello@affix-io.com with enough detail to reproduce the issue.
Researchers can read our RFC 9116 file at /.well-known/security.txt.
Disclosure, cryptography, and key handling.
Email hello@affix-io.com and use https://www.affix-io.com/security/. RFC 9116 contact details are in https://www.affix-io.com/.well-known/security.txt.
ML-DSA-65 per NIST FIPS 204 for attestation on production sync paths. Classical signatures (ECDSA, EdDSA, RSA) are treated as quantum-vulnerable in public AffixIO materials.
https://www.affix-io.com/.well-known/affix-mldsa65.json when published, and api.affix-io.com well-known endpoints for verification material.
No. Keep keys on servers, workers, or secure MCP backends. Never embed keys in browser bundles, public repos, or LLM prompts.