This document outlines our security policy and guidelines on disclosing vulnerabilities. We use github Security Advisory to manage the process, so please ensure you've 2FA enabled on your github account before disclosing any vulnerability.
- Create a security advisory on github
- Include a demonstration or a POC along with detailed bug report.
- A member from our security team will look into it with in 48 hours. If you haven't received any acknowledgement please send an email to
[email protected]
and escalate it.
We really appreciate your interest in helping us keep things secure and serving the ecosystem better.
We haven't undergone any 3rd party security audits. However, we do expect to conduct a thorough audit in the future.
Due to financial constraints, we do not currently have a paid bug bounty program. We expect this to change in the future, although do not guarantee it, in which case retrospective grants will be considered on a case by case basis.