Skip to content

Security: Ando-OSS/mpp-i

Security

SECURITY.md

Security Policy

MPP-I is currently a protocol paper and early public specification repository.

Reporting Security Issues

If you find a security issue in the protocol design, examples, schemas, or future libraries, please email:

jamie@alethieum.com

For non-sensitive protocol questions, open a GitHub Discussion or Issue.

Current Scope

In scope:

  • protocol accounting issues,
  • payment-state binding issues,
  • replay or double-settlement risks,
  • privacy leaks in payment/control-plane design,
  • unsafe future schemas or examples.

Out of scope:

  • issues in third-party payment systems,
  • issues in unrelated MPP or x402 implementations,
  • legal, compliance, tax, or regulatory advice.

There aren't any published security advisories