Current documentation
Security Documentation Requirements
Minimum security documentation required before any revived component can be described as supported.
1. Required documentation
- •Threat model and trust boundaries.
- •Authentication and key-management design.
- •Dependency and update policy.
- •Supported versions and security-fix expectations.
- •Responsible vulnerability disclosure process.
2. Release requirements
- •Automated tests for security-sensitive behaviour.
- •Review of externally reachable interfaces.
- •Signed or otherwise verifiable release artifacts.
- •Accurate record of known limitations.
- •No unsupported privacy or encryption claims.
3. Historical warning
Historical ZRTP and secure-calling material remains valuable technical history. It must not be interpreted as a security assessment of any future implementation.
Interested in helping before the public repository opens? Contact TwoSquares with your area of interest or any historical material you can verify.