Skip to content

feat(security): update security policy with bug bounty program and reward matrix - #1373

Merged
joelpeace48-cell merged 1 commit into
FinesseStudioLab:mainfrom
ArtyormSatori:feat/security-disclosure-bug-bounty-policy
Sep 25, 2026
Merged

joelpeace48-cell merged 1 commit into
FinesseStudioLab:mainfrom
ArtyormSatori:feat/security-disclosure-bug-bounty-policy

Conversation

@ArtyormSatori

Copy link
Copy Markdown

Summary of Changes

This pull request fulfills Issue #1310 by establishing a formal Security Vulnerability Disclosure Policy and Bug Bounty Reward Matrix for Trivela.

Detailed Scope:

  1. Bug Bounty Reward Matrix: Structured 4-tier financial reward policy (Critical $2,500-$5,000+, High $1,000-$2,500, Medium $300-$1,000, Low $100-$300) based on CVSS v3.1 and ecosystem impact.
  2. Responsible Disclosure Protocol: Directs reports to GitHub Private Security Advisories and encrypted security email security@finessestudiolab.com.
  3. Architectural Scope: Defines in-scope components (/contracts/, /soroban/, /backend/, /sdk/, /frontend/) and out-of-scope boundaries.
  4. Safe Harbor & SLA: Guarantees safe harbor for ethical researchers and sets clear 24-48h initial response SLA.

Closes #1310

…ward matrix

- Add formal bug bounty reward tiers (Critical to Low) based on CVSS v3.1
- Detail private vulnerability disclosure channels via GitHub Advisory and email
- Outline supported components, in-scope/out-of-scope boundaries, and safe harbor
- Establish triage response times and SLA commitments

Closes FinesseStudioLab#1310
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(security): Security Vulnerability Disclosure policy (SECURITY.md) and bug bounty program

3 participants