| Version | Supported |
|---|---|
| 0.x | ✅ |
If you discover a security vulnerability within Verity, please send an email to security@verityprotocol.dev. All security vulnerabilities will be promptly addressed.
Please do not report security vulnerabilities through public GitHub issues.
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix or mitigation: Depends on severity, typically within 2 weeks
This security policy applies to:
verity-contracts— Soroban smart contractsverity-backend— NestJS API serververity-frontend— Next.js web application
We are currently in pre-launch. A formal bug bounty program will be announced at launch.
We prefer vulnerability reports in English.