Security & trust
We are asking to sit in your privileged path.
That deserves more than a trust badge. Here is how the product is built, what we assure, what we explicitly do not claim, and how to tell us when we have got something wrong.
Product security
Properties enforced by the build, not by convention.
No setuid binary, anywhere
The client carries zero authority. A non-setuid daemon is the only decision point, and exactly one audited privilege transition performs the spawn — gated in CI so a second cannot appear.
Memory-safe by construction
Written in Rust. The privileged dependency closure is gated to a small fixed set of crates and enforced on every build.
Policy verified before it loads
Policy is compiled ahead of time and MAC-verified before the socket opens. A bad key or bad MAC means the daemon refuses to start rather than running open.
Minimal trusted computing base
The privileged workspace is deliberately separate from the daemon tooling, so the code running with authority stays small enough to review.
Confinement fails closed
A permit naming a sandbox the host cannot arm does not silently run unconfined — the command aborts before exec.
Audit you can verify without us
Records are ed25519-signed and hash-chained, streamed off-host over mTLS. Verification needs neither our software nor our cooperation.
How we build
Development
- Every change reviewed before merge; no direct pushes to the release branch
- Dedicated CI gates for the privileged path, including a single-privilege-transition check
- Dependency closure pinned and diffed on every build
- Fuzzing and differential testing against the reference implementation
Supply chain
- CycloneDX SBOM generated per shipped binary
- SBOM pinned against drift in CI — a dependency change cannot ship silently
- Release artifacts GPG-signed; signatures travel with the package
- Advisory expiry checks fail the build when a known issue ages out
Vulnerability management
- The full sudo CVE corpus is classified against our architecture
- The classification manifest is enforced bidirectionally in CI
- A newly published CVE fails the build until it is triaged
- Findings from our own classification work are fixed and documented, not quietly closed
Responsible disclosure
If you have found a vulnerability, we want to hear about it before anyone else does. Write to security@evren.co.
Safe harbour
We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy. We consider that research authorised, we will not report you to law enforcement for it, and we will not treat it as a breach of our terms of service.
If a third party brings action against you for research conducted under this policy, we will make that authorisation known.
What we ask of you
- Give us reasonable time to remediate before any public disclosure.
- Avoid privacy violations, data destruction, and interruption of service.
- Only interact with accounts and systems you own or have permission to test.
- Do not access, modify or retain data belonging to anyone else — stop as soon as you have proof.
- Do not use social engineering, physical attacks, or denial of service.
Scope
In scope
- The Evren daemon, client, spawner and policy engine
- The audit pipeline, signing and verification tooling
- Released packages and their signatures
- evren.co and services we operate
Out of scope
- Denial of service and volumetric testing
- Findings that require host root you already hold
- Third-party services we do not operate
- Reports from automated scanners with no demonstrated impact
What happens next
Within 2 business days
We acknowledge your report and give you a named contact.
Within 10 business days
We confirm whether we have reproduced it and give you our assessment.
While we work
You get progress updates, not silence.
On release
We credit you in the advisory unless you would rather we did not.
Contact
- security@evren.co
- Policy file
- /.well-known/security.txt
- Encryption
- PGP key on request. We accept plain email — do not let key exchange delay a report.
We do not currently run a paid bounty programme. We do credit every valid report.