Skip to content

Security: prismnetwork-tech/prism-contracts

SECURITY.md

Security policy

Supported versions

The contracts are pre-production and unaudited. Security fixes apply to the current main branch. No deployment or release currently receives long-term support.

Reporting a vulnerability

Do not open a public issue.

Use GitHub private vulnerability reporting for this repository. If that channel is unavailable, email security@prismnetwork.tech with affected code, reproduction steps, impact and prerequisites.

Do not test against public infrastructure, deployed contracts or real funds. Use a local chain or private fork with accounts you control.

Explicit non-guarantees

The contracts do not prove:

  • Correct GPU execution.
  • Honest node telemetry or gateway observations.
  • Supplier trustworthiness or confidential computing.
  • Correctness of offchain proof publication.

The attestor, gateway, Safe and deployment process remain critical trust boundaries.

There aren't any published security advisories