Security

Responsible disclosure & bounty

We take security seriously. If you find a vulnerability, please tell us first — we'll fix it fast, credit you publicly (with your permission), and pay a bounty for qualifying reports.

How to report

Email security@vectorialdata.com with:

We acknowledge reports within 48 hours and aim to ship a fix or mitigation within 14 days for critical findings.

Scope

In scope:

Out of scope:

Rewards

Bounties are paid in USDC, scaled to severity and quality of report. We use a standard CVSS-aligned scale, with judgment for real impact on user funds:

Bounties require: first to report, not publicly disclosed, no user-data exfiltration, and good-faith testing only on your own accounts.

Safe harbor

Research conducted in good faith and consistent with this policy will not result in legal action. Don't access or modify data that isn't yours, don't degrade service, and don't test on real user accounts — use your own.

Machine-readable

Our security.txt follows RFC 9116.