Trust boundary
Security
MOV's local Runtime Acceptance path is designed to minimize the authority and secrets it needs. Security reports are welcome and should be sent privately.
Report a vulnerability
Email sarmad@machineoutcome.com with the subject “MOV security report”. Include the affected surface/version, reproduction steps, impact and any safe supporting evidence.
Please do not include private keys, seed phrases, wallet secrets, API keys, customer data, or other unnecessary secrets in a report.
Current security boundary
- The public local acceptance path performs no purchase, signer invocation or runtime-secret read.
- MOV does not take custody of buyer funds.
- Live payment/signing is a separate explicit authorization boundary.
- Required but missing, contradictory or non-final evidence must resolve to
UNKNOWN, not acceptance. - Version-pinned deterministic verifiers and exact evidence binding are part of the current kernel design.
Coordinated handling
Give us a reasonable opportunity to investigate and fix a material issue before public disclosure. Do not intentionally access unrelated accounts/data, degrade service, or create financial side effects while testing.
Security.txt
A machine-readable disclosure contact is published at /.well-known/security.txt.