Security
Responsible disclosure, and the posture the products ship with.
Reporting
Send the report to the security address, not the general contact address.
A report is triaged and remediation is coordinated from that channel. Include what is needed to reproduce it.
Which product, which surface, and which version or deployment shape.
The steps, inputs, and conditions needed to observe the issue.
How to reach you to coordinate remediation and disclosure.
Do not send credentials, private keys, regulated health information, payment-card data, or confidential corpora through the general contact channel. Use the security or legal review path so a suitable NDA, transfer channel, and retention policy can be established first.
Product posture
Verification does not require trust in HolonomiX.
Receipts, evidence bundles, and posture snapshots verify without a network connection and without a HolonomiX endpoint. This is the path that survives an outage, an issuer change, or a multi-decade retention requirement.
On the Private Appliance surfaces, signing keys are generated on the appliance at first boot, stay under customer-controlled permissions, and never leave the customer environment.
Appliance and Air-Gapped edition deployments operate with no outbound connectivity. Entitlement install, verification, and rotation work offline.
Every shipped file is hashed and the manifest is signed with an offline release key. Releases ship with a CycloneDX SBOM, a vulnerability scan report, build provenance, a validation summary, and a signed release attestation.
A release-blocking validation harness ships with the appliance so the customer security team can run it independently.
Cryptographic posture
NIST-standardized algorithms where implemented.
The HX-Provenance cryptographic module is built to FIPS 140-3 architecture, addressing the eleven security requirement areas defined by ISO/IEC 19790. CAVP algorithm validation and CMVP module validation are on the enterprise roadmap, gated by buyer commitment; the module is built to the standard, and the certificate path runs against an enterprise contract.
Elsewhere in the portfolio, including the HX-PQC Lifecycle Platform, the claim is that HolonomiX uses NIST-standardized algorithms where implemented. No FIPS 140-3 or CMVP validation is claimed unless a validated module certificate supports the exact deployment.