Skip to content

Security: Dev-AdeTutu/stellar-app-os

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

We run a bug bounty program on Immunefi — all vulnerability reports should be submitted there. Immunefi handles triage, communication, and reward payouts.

Search for "Harvesta" or "Stellar App OS" on Immunefi to find our program.

For full program details — scope, severity levels, reward amounts, and rules of engagement — see docs/BUG_BOUNTY.md.

Scope Summary

Category Examples
In scope Soroban smart contracts, API endpoints, webhook system, indexer
Out of scope Frontend UI/UX, third-party deps, Stellar network itself, social engineering

Severity & Rewards

Severity Reward
Critical Up to $25,000
High Up to $15,000
Medium Up to $5,000
Low Up to $1,000

Response SLA

  • Initial response: 48 hours
  • Triage: 7 days
  • Resolution: 30 days (severity-dependent)

Safe Harbor

Researchers who follow responsible disclosure guidelines will not face legal action. See docs/BUG_BOUNTY.md for the full safe harbor statement.

Contact

There aren't any published security advisories