Skip to content

Security: andrewSarr/raio

Security

SECURITY.md

Security policy

Status: foundation, not a payment system

raio v0.1 ships core libraries and documentation only. It deliberately includes no network servers, no transport, and no production settlement implementation. Treat it as a toolkit for building a payment rail, not as a payment rail itself.

The settlement caveat

SettlementProvider (in raio-core) is an abstract trait. The only implementation in this repository is the settlement_demo example's naive in-memory netting — a teaching aid, not safe for real money. Anyone moving real value must supply their own settlement provider backed by a real RTGS / custody / reserve arrangement. Do not use the naive demo impl for production settlement.

Reporting a vulnerability

If you believe you have found a security-relevant defect (e.g. a way to make the ledger inconsistent, a money-arithmetic overflow, a BR Code that mis-decodes), please do not open a public issue. Instead:

  1. Email the maintainers (see the repo's security advisories / contact channel).
  2. Include a minimal reproduction and the affected crate + version.
  3. Allow up to 72 hours for an initial acknowledgement.

We will coordinate disclosure timing with you and credit your report.

Hardening boundaries

The following are intentionally out of scope for this foundation and must be supplied by the deployment that builds on top of it:

  • authentication, authorization, and identity attestation of participants,
  • transport-level security (TLS, mTLS, message signing),
  • replay / idempotency enforcement across a network (the in-process IdempotencyKey contract is defined in raio-core; the wire-level enforcement belongs to the future rail crate),
  • durable, ACID storage for LedgerStore / KeyDirectory,
  • a real SettlementProvider.

A deployment that omits any of the above is responsible for the resulting risk.

There aren't any published security advisories