Skip to content
HolonomiX

Security

Responsible disclosure, and the posture the products ship with.

Report a vulnerability security@holonomx.com

Reporting

Send the report to the security address, not the general contact address.

A report is triaged and remediation is coordinated from that channel. Include what is needed to reproduce it.

Affected surface

Which product, which surface, and which version or deployment shape.

Reproduction details

The steps, inputs, and conditions needed to observe the issue.

Reporter contact

How to reach you to coordinate remediation and disclosure.

Do not send credentials, private keys, regulated health information, payment-card data, or confidential corpora through the general contact channel. Use the security or legal review path so a suitable NDA, transfer channel, and retention policy can be established first.

Product posture

Verification does not require trust in HolonomiX.

Offline verification

Receipts, evidence bundles, and posture snapshots verify without a network connection and without a HolonomiX endpoint. This is the path that survives an outage, an issuer change, or a multi-decade retention requirement.

Customer key custody

On the Private Appliance surfaces, signing keys are generated on the appliance at first boot, stay under customer-controlled permissions, and never leave the customer environment.

Air-gapped operation

Appliance and Air-Gapped edition deployments operate with no outbound connectivity. Entitlement install, verification, and rotation work offline.

Release evidence

Every shipped file is hashed and the manifest is signed with an offline release key. Releases ship with a CycloneDX SBOM, a vulnerability scan report, build provenance, a validation summary, and a signed release attestation.

Self-validation

A release-blocking validation harness ships with the appliance so the customer security team can run it independently.

Cryptographic posture

NIST-standardized algorithms where implemented.

Signing ML-DSA-65 FIPS 204
Key encapsulation ML-KEM-768 FIPS 203
Data encryption AES-256-GCM FIPS 197 / SP 800-38D

The HX-Provenance cryptographic module is built to FIPS 140-3 architecture, addressing the eleven security requirement areas defined by ISO/IEC 19790. CAVP algorithm validation and CMVP module validation are on the enterprise roadmap, gated by buyer commitment; the module is built to the standard, and the certificate path runs against an enterprise contract.

Elsewhere in the portfolio, including the HX-PQC Lifecycle Platform, the claim is that HolonomiX uses NIST-standardized algorithms where implemented. No FIPS 140-3 or CMVP validation is claimed unless a validated module certificate supports the exact deployment.

Contact

Responsible disclosure security@holonomx.com
Evaluation and access access@holonomx.com