This policy covers:
- Anchor program (
anchor/programs/pm_amm/) — on-chain smart contract - API routes (
app/src/app/api/) — server-side endpoints - Math implementation (
pm_math.rs,accrual.rs) — financial calculations
Please report security vulnerabilities by emailing github.com.mattdgn.p.demeanor108@passmail.net.
- Do not open a public issue for security vulnerabilities.
- Include steps to reproduce and potential impact.
- You will receive an acknowledgment within 48 hours.
No formal bug bounty program exists at this time. We appreciate responsible disclosures and will credit reporters in our changelog.
- Devnet-only issues (test environment)
- Social engineering
- Denial of service against public RPC endpoints
- Issues in third-party dependencies (report upstream)