Skip to content

Security

Last updated June 2026

FleetGate touches the firewall on every host you run, so security is the whole point. We take reports seriously and would much rather hear about a problem from you than read about it somewhere else.

Reporting a vulnerability

Email honk@militantgoose.dev with enough detail to reproduce the issue. If you would like to encrypt, ask for our public key in your first message. Please give us a reasonable window to remediate before any public disclosure.

Scope

This covers the FleetGate control plane and host enforcer, and this marketing site (fleetgate.dev). The marketing site holds only waitlist emails and has no connection to the control plane — but we still want to know if something is wrong with it.

Verifying releases

The enforcer ships as a GPG-signed .deb/.rpm. Import our public key and your package manager verifies every release — see the verify section.

What to expect

We will acknowledge your report, keep you updated as we investigate, and credit you once a fix ships — unless you would prefer to stay anonymous. This is a draft policy and will be expanded as FleetGate approaches general availability.