Momento is now post-quantum — v2 receipts use ML-DSA-65. Learn more →⚠️ npm delayed — recovery requested, awaiting npm support. How to use Momento meanwhile →
Momento Timestamp

Security policy

Reporting vulnerabilities and understanding security scope.

Momento Timestamp is a community project. The v2 release is being prepared; once published, security fixes will target the latest 2.x release. There is no guaranteed response time or uptime commitment.

Report privately

Use GitHub private vulnerability reporting. Include affected versions, reproduction steps, and the impact. Do not send private signing keys, access tokens, or sensitive original files.

If private reporting is unavailable, open an issue requesting a private contact without revealing exploit details. Maintainers should enable private vulnerability reporting before the release.

Scope and trust

Report signature bypasses, parser inconsistencies, secret exposure, unexpected file uploads, receipt tampering, or exploitable resource exhaustion. The documented ability of the signing-key holder to backdate new receipts is a current design limit. See the threat model and key lifecycle.

Receipts authenticate the issuer's statement about a hash and time. They do not certify an independent clock, authorship, ownership, RFC 3161 compliance, or a legal conclusion. Keep an authentic public key and original bytes for independent verification.

On this page