Do not open a public GitHub issue for security vulnerabilities.
We run bug bounty programs on HackerOne and Immunefi — all vulnerability reports should be submitted there. The platforms handle triage, communication, and reward payouts.
Search for "Harvesta" or "Stellar App OS" on HackerOne or Immunefi to find our program.
For full program details — scope, severity levels, tiered reward amounts, and rules of engagement — see:
docs/HACKERONE_BUG_BOUNTY.md(HackerOne)docs/BUG_BOUNTY.md(Immunefi)
| Category | Examples |
|---|---|
| In scope | Soroban smart contracts, API endpoints, webhook system, indexer |
| Out of scope | Frontend UI/UX, third-party deps, Stellar network itself, social engineering |
| Severity | Reward |
|---|---|
| Critical | Up to $25,000 |
| High | Up to $15,000 |
| Medium | Up to $5,000 |
| Low | Up to $1,000 |
- Initial response: 48 hours
- Triage: 7 days
- Resolution: 30 days (severity-dependent)
Researchers who follow responsible disclosure guidelines will not face legal action. See docs/HACKERONE_BUG_BOUNTY.md and docs/BUG_BOUNTY.md for the full safe harbor statements.
- HackerOne: Submit a report
- Immunefi: Submit a report
- Email: security@harvesta.io