COORDINATED DISCLOSURE TIMELINES

Safety Timeline &
Coordinated Disclosures

We operate under a strict 90-day coordinated disclosure policy. Vulnerabilities found on commercial targets are reported immediately and held private for mitigation.

Active Vulnerability Advisories

02 / THE 90-DAY CLOCK

Disclosure Policy

1. Discovery & Verification

WRAITH identifies a safety bypass, logs seed hashes, and verifies the exploit is reproducible.

2. Private Notification

Advisories are sent securely to vendors via PGP encrypted email, initiating the 90-day timer.

3. Mitigation Grace Period

Vendors are granted 90 days to issue system prompt mitigations or weights guardrail updates.

4. Public Disclosure

Upon patch release or clock expiration, the advisory is published with sanitized payloads.

03 / SECURE REPORTING

Report a Bypass

Found a novel jailbreak or security bypass? Securely dispatch details using our PGP public keys.

security@wraith-sec.org
PGP KEY BLOCK
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP.js v4.10.10
Comment: WRAITH Safety & Disclosure Key

mQENBF+S2dIBCAD3V/a2K0D8L5/uJ7b4r1r5wQkI2F4kLz8vO9n/Jg7wQ==
=12fG
-----END PGP PUBLIC KEY BLOCK-----