Security
Last updated June 2026
FleetGate touches the firewall on every host you run, so security is the whole point. We take reports seriously and would much rather hear about a problem from you than read about it somewhere else.
Reporting a vulnerability
Email honk@militantgoose.dev with enough detail to reproduce the issue. If you would like to encrypt, ask for our public key in your first message. Please give us a reasonable window to remediate before any public disclosure.
Scope
This covers the FleetGate control plane and host enforcer, and this marketing site (fleetgate.dev). The marketing site holds only waitlist emails and has no connection to the control plane —
but we still want to know if something is wrong with it.
Verifying releases
The enforcer ships as a GPG-signed .deb/.rpm. Import our public key
and your package manager verifies every release — see the verify section.
What to expect
We will acknowledge your report, keep you updated as we investigate, and credit you once a fix ships — unless you would prefer to stay anonymous. This is a draft policy and will be expanded as FleetGate approaches general availability.