Security fixes target the latest minor release on main.
Do not open a public issue for a suspected vulnerability. Use GitHub's private security-advisory reporting flow for this repository and include:
- affected version or commit;
- reproduction steps;
- security impact;
- suggested mitigation, when available.
KeyVeil is a policy-decision reference. It does not sign or execute payments. Reports about an integration should distinguish KeyVeil behavior from the external signer, budget backend, approval service, and execution adapter.