SECURITY

Open systems require verifiable security.

Nine measures are named in the protocol design. Three of them hold today, and this page says which.

testnet The chain runs on a public testnet. Mainnet has not launched, the marketplace is not built, and the source is not yet public — each measure below carries its own state.

01 · THE NINE MEASURES

The nine measures

Not nine equal items. The variation between them is the section.

MeasureStateWhat it means today
Decentralized consensustestnetkHeavyHash proof-of-work, running on the public testnet at a 10-second target.
Cryptographic verificationtestnetProof-of-work verification and workshares, running today.
Transparent protocol rulestestnetConsensus, difficulty, rewards and locking are documented in the docs.
Open-source softwareNot yet inspectableNamed as a measure, but the source has not been published. See section 02.
Independent auditsNone yetNo audit has been commissioned. See section 04.
Responsible disclosurePolicy pendingAn address exists; a formal policy does not. See section 03.
Provider collateralplannedArrives with the financial provider network.
Execution receiptsplannedArrives with the marketplace layer.
Economic penaltiesplannedArrives with the provider framework, where appropriate.

Three of the nine hold today. Three are pending the marketplace layer. One has no audit, one has no formal policy, and one is claimed but not yet inspectable.

02 · WHAT CAN BE VERIFIED TODAY

What can be verified today

The rules are documented and checkable. The source is not public yet.

Checkable against a node you build

  • The consensus rules
  • The difficulty algorithm
  • The reward and locking model
  • The RPC surface

Each of these is documented and can be checked against a node you build and run yourself, against the public testnet.

Not yet inspectable

The source is not public. The organisation at github.com/kronexnetwork holds no repositories, and the chain's code has not landed there.

Open-source software is named as one of the nine measures. Until the code is published, that measure is a statement of intent rather than something a reader can act on, and this page does not count it among the three that hold.

No publication date has been set. When one is, it will appear here.

  • github.com/kronexnetwork — empty
  • clone URL — 404

What a reader can do today is build a node from the documented rules and check the chain against it. What a reader cannot do today is read the implementation.

03 · REPORTING A VULNERABILITY

Reporting a vulnerability

An address that works, and a formal policy that does not exist yet.

Contact

contact@kronex.network

The only published address. There is no separate security alias.

What to include

  • affected component
  • chain ID
  • node version
  • reproduction steps

What not to do

  • ✗ test against infrastructure you do not run
  • ✗ publish before we have replied

Specification pendingThere is no formal disclosure policy. A researcher needs a defined scope, a response time and a safe-harbour statement before reporting, and none of the three has been drafted. Safe harbour in particular is a legal commitment and is not granted by this page. What exists today is an address and a commitment to read it.

04 · AUDITS

Audits

AuditorScopeDateReport
No independent audit has been commissioned.

The columns a real audit row would use are present and empty. The day a report exists it becomes a row here, with a link to the report itself.

05 · BUG BOUNTY

Bug bounty

    A bug bounty is planned and will be published with the disclosure policy. No reward structure has been decided, and none is stated here: a reward is a financial commitment, and inventing one would be as dishonest as inventing a fee.

    06 · CONTINUOUS, NOT A FEATURE

    Continuous, not a feature

    Security is a continuous process rather than a single feature.