SEMAPRAX is pre-alpha and not suitable for production or safety-critical software. Security guarantees described in the RFC are design goals unless the README lists them as implemented.
Please report vulnerabilities privately through GitHub's security advisory feature for wavect/semaprax. Do not open a public issue for an undisclosed vulnerability.
Reports should include the affected revision, host platform, minimal source or patch input, observed impact, and reproduction steps. We will acknowledge a complete report as soon as practical and coordinate disclosure after a fix is available.