NewA botnet shipped no malware at all — the payload was 39 lines of English
Evren

Security & trust

We are asking to sit in your privileged path.

That deserves more than a trust badge. Here is how the product is built, what we assure, what we explicitly do not claim, and how to tell us when we have got something wrong.

Product security

Properties enforced by the build, not by convention.

No setuid binary, anywhere

The client carries zero authority. A non-setuid daemon is the only decision point, and exactly one audited privilege transition performs the spawn — gated in CI so a second cannot appear.

Memory-safe by construction

Written in Rust. The privileged dependency closure is gated to a small fixed set of crates and enforced on every build.

Policy verified before it loads

Policy is compiled ahead of time and MAC-verified before the socket opens. A bad key or bad MAC means the daemon refuses to start rather than running open.

Minimal trusted computing base

The privileged workspace is deliberately separate from the daemon tooling, so the code running with authority stays small enough to review.

Confinement fails closed

A permit naming a sandbox the host cannot arm does not silently run unconfined — the command aborts before exec.

Audit you can verify without us

Records are ed25519-signed and hash-chained, streamed off-host over mTLS. Verification needs neither our software nor our cooperation.

How we build

Development

  • Every change reviewed before merge; no direct pushes to the release branch
  • Dedicated CI gates for the privileged path, including a single-privilege-transition check
  • Dependency closure pinned and diffed on every build
  • Fuzzing and differential testing against the reference implementation

Supply chain

  • CycloneDX SBOM generated per shipped binary
  • SBOM pinned against drift in CI — a dependency change cannot ship silently
  • Release artifacts GPG-signed; signatures travel with the package
  • Advisory expiry checks fail the build when a known issue ages out

Vulnerability management

  • The full sudo CVE corpus is classified against our architecture
  • The classification manifest is enforced bidirectionally in CI
  • A newly published CVE fails the build until it is triaged
  • Findings from our own classification work are fixed and documented, not quietly closed

Responsible disclosure

If you have found a vulnerability, we want to hear about it before anyone else does. Write to security@evren.co.

Safe harbour

We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy. We consider that research authorised, we will not report you to law enforcement for it, and we will not treat it as a breach of our terms of service.

If a third party brings action against you for research conducted under this policy, we will make that authorisation known.

What we ask of you

  • Give us reasonable time to remediate before any public disclosure.
  • Avoid privacy violations, data destruction, and interruption of service.
  • Only interact with accounts and systems you own or have permission to test.
  • Do not access, modify or retain data belonging to anyone else — stop as soon as you have proof.
  • Do not use social engineering, physical attacks, or denial of service.

Scope

In scope

  • The Evren daemon, client, spawner and policy engine
  • The audit pipeline, signing and verification tooling
  • Released packages and their signatures
  • evren.co and services we operate

Out of scope

  • Denial of service and volumetric testing
  • Findings that require host root you already hold
  • Third-party services we do not operate
  • Reports from automated scanners with no demonstrated impact

What happens next

  1. Within 2 business days

    We acknowledge your report and give you a named contact.

  2. Within 10 business days

    We confirm whether we have reproduced it and give you our assessment.

  3. While we work

    You get progress updates, not silence.

  4. On release

    We credit you in the advisory unless you would rather we did not.

Contact

Encryption
PGP key on request. We accept plain email — do not let key exchange delay a report.

We do not currently run a paid bounty programme. We do credit every valid report.