| Version | Supported |
|---|---|
| main | ✅ |
If you discover a security vulnerability in Trivela, please report it responsibly:
- Do NOT open a public GitHub issue.
- Email security@finessestudiolab.com with:
- A description of the vulnerability
- Steps to reproduce
- Impact assessment
- You will receive an acknowledgement within 48 hours.
- We will work with you to understand and address the issue before any public disclosure.
- Smart contracts (
/contracts/,/soroban/) - Backend API (
/backend/) - SDK and client libraries (
/sdk/) - Frontend application (
/frontend/)
We do not currently operate a formal bug bounty programme, but we appreciate responsible disclosures and will credit reporters in our release notes (with permission).