Skip to content

Security: Veritas-Vaults-Network/Soroban-Guard-web

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main ✅ Yes

Only the latest code on the main branch receives security fixes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report them via one of the following:

Include as much detail as possible: steps to reproduce, affected component, and potential impact.

Response Timeline

Milestone Target
Acknowledgement Within 48 hours
Status update Within 7 days
Patch / fix released Within 14 days of confirmation

We will coordinate a disclosure date with you once a fix is ready.

Out of Scope

The following are not considered in-scope vulnerabilities:

  • Bugs in third-party dependencies (report upstream)
  • Issues in the Stellar network or Soroban protocol itself
  • Freighter wallet internals
  • Findings from automated scanners without a working proof-of-concept
  • Social engineering or phishing attacks

Disclosure Policy

We follow responsible disclosure. Please give us reasonable time to address the issue before any public disclosure.

There aren't any published security advisories