Do not open a public GitHub issue for security vulnerabilities.
We run a bug bounty program on Immunefi — all vulnerability reports should be submitted there. Immunefi handles triage, communication, and reward payouts.
Search for "Harvesta" or "Stellar App OS" on Immunefi to find our program.
For full program details — scope, severity levels, reward amounts, and rules of engagement — see docs/BUG_BOUNTY.md.
| Category | Examples |
|---|---|
| In scope | Soroban smart contracts, API endpoints, webhook system, indexer |
| Out of scope | Frontend UI/UX, third-party deps, Stellar network itself, social engineering |
| Severity | Reward |
|---|---|
| Critical | Up to $25,000 |
| High | Up to $15,000 |
| Medium | Up to $5,000 |
| Low | Up to $1,000 |
- Initial response: 48 hours
- Triage: 7 days
- Resolution: 30 days (severity-dependent)
Researchers who follow responsible disclosure guidelines will not face legal action. See docs/BUG_BOUNTY.md for the full safe harbor statement.
- Immunefi: Submit a report
- Email: security@harvesta.io