Skip to content

Security: verity-protocol/verity-backend

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x

Reporting a Vulnerability

If you discover a security vulnerability within Verity, please send an email to security@verityprotocol.dev. All security vulnerabilities will be promptly addressed.

Please do not report security vulnerabilities through public GitHub issues.

What to include

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix or mitigation: Depends on severity, typically within 2 weeks

Scope

This security policy applies to:

  • verity-contracts — Soroban smart contracts
  • verity-backend — NestJS API server
  • verity-frontend — Next.js web application

Bug Bounty

We are currently in pre-launch. A formal bug bounty program will be announced at launch.

Preferred Languages

We prefer vulnerability reports in English.

There aren't any published security advisories