All security vulnerabilities can be reported to [[mailto:security@trustedfirmware.org]]. Alternatively, there are project specific aliases that can be used:
**OP-TEE**
[[mailto:op-tee-security@lists.trustedfirmware.org]]
**Trusted-Firmware-A**
[[mailto:tf-a-security@lists.trustedfirmware.org]]
**Trusted-Firmware-M**
[[mailto:tf-m-security@lists.trustedfirmware.org]]
**Mbed TLS**
[[mailto:mbed-tls-security@lists.trustedfirmware.org]]
If you choose to encrypt your report, the same [[ https://developer.trustedfirmware.org/w/collaboration/security_center/pgp_keys/ | PGP key ]] may be used for any of these aliases.