Skip to content

Security: FinesseStudioLab/Trivela

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main

Reporting a Vulnerability

If you discover a security vulnerability in Trivela, please report it responsibly:

  1. Do NOT open a public GitHub issue.
  2. Email security@finessestudiolab.com with:
    • A description of the vulnerability
    • Steps to reproduce
    • Impact assessment
  3. You will receive an acknowledgement within 48 hours.
  4. We will work with you to understand and address the issue before any public disclosure.

Scope

  • Smart contracts (/contracts/, /soroban/)
  • Backend API (/backend/)
  • SDK and client libraries (/sdk/)
  • Frontend application (/frontend/)

Bug Bounty

We do not currently operate a formal bug bounty programme, but we appreciate responsible disclosures and will credit reporters in our release notes (with permission).

There aren't any published security advisories