Security fixes are applied to the active main branch and released deployments maintained by the project team.
Please do not open a public GitHub issue for security reports.
Instead, email the maintainers with:
- A clear description of the issue
- Steps to reproduce (if applicable)
- Impact assessment and suggested mitigation, if known
We aim to acknowledge reports within a few business days and will coordinate disclosure timelines with reporters when possible.
Reports related to Payoes application security, deployment configuration, and published Soroban contracts are in scope. Third-party services (hosting providers, wallets, identity vendors) should be reported to those vendors directly when appropriate.