Momento is now post-quantum — v2 receipts use ML-DSA-65. Learn more →⚠️ npm delayed — recovery requested, awaiting npm support. How to use Momento meanwhile →

Security

Report a vulnerability privately

Please use GitHub private vulnerability reporting. Include reproduction steps and the affected version. Do not include private signing keys or sensitive original files.

If reporting is unavailable, open a public issue asking for a private contact without disclosing the vulnerability. This community project has no guaranteed response time.

What you can trust

The original file stays on your device. Receipts bind a SHA-256 hash to the issuer's stated time. A signature does not establish authorship, ownership, independently certified UTC accuracy, or protection against issuer backdating.

Read the full trust model