Skip to content

Security: Fading-Dev/stellar-app-os

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

We run bug bounty programs on HackerOne and Immunefi — all vulnerability reports should be submitted there. The platforms handle triage, communication, and reward payouts.

Search for "Harvesta" or "Stellar App OS" on HackerOne or Immunefi to find our program.

For full program details — scope, severity levels, tiered reward amounts, and rules of engagement — see:

Scope Summary

Category Examples
In scope Soroban smart contracts, API endpoints, webhook system, indexer
Out of scope Frontend UI/UX, third-party deps, Stellar network itself, social engineering

Severity & Rewards

Severity Reward
Critical Up to $25,000
High Up to $15,000
Medium Up to $5,000
Low Up to $1,000

Response SLA

  • Initial response: 48 hours
  • Triage: 7 days
  • Resolution: 30 days (severity-dependent)

Safe Harbor

Researchers who follow responsible disclosure guidelines will not face legal action. See docs/HACKERONE_BUG_BOUNTY.md and docs/BUG_BOUNTY.md for the full safe harbor statements.

Contact

There aren't any published security advisories