Responsible disclosure & bounty
We take security seriously. If you find a vulnerability, please tell us first — we'll fix it fast, credit you publicly (with your permission), and pay a bounty for qualifying reports.
How to report
Email security@vectorialdata.com with:
- A clear description of the issue and impact.
- Reproduction steps (or a proof-of-concept).
- The affected URL, endpoint, or contract.
- Your preferred name/handle for public credit (optional).
We acknowledge reports within 48 hours and aim to ship a fix or mitigation within 14 days for critical findings.
Scope
In scope:
terminal.vectorialdata.comand its API endpoints- Authentication, signing, and balance flows on the terminal
- Smart-contract integrations we wrote (builder code config, treasury setters)
Out of scope:
- Vulnerabilities in third-party protocols we integrate (Hyperliquid, Polymarket, Circle CCTP, Privy) — please report to them directly
- Denial-of-service, volumetric attacks, or rate-limit testing without prior written consent
- Social engineering, phishing, or physical attacks against our team
- Reports based on automated scanners with no demonstrated impact
- Best-practice issues without exploit (missing security headers on static pages, etc.)
Rewards
Bounties are paid in USDC, scaled to severity and quality of report. We use a standard CVSS-aligned scale, with judgment for real impact on user funds:
- Critical (fund loss, signing bypass): up to $25,000
- High (privilege escalation, data exfiltration): up to $8,000
- Medium (sensitive data leak without fund risk): up to $2,000
- Low (limited impact): up to $500
Bounties require: first to report, not publicly disclosed, no user-data exfiltration, and good-faith testing only on your own accounts.
Safe harbor
Research conducted in good faith and consistent with this policy will not result in legal action. Don't access or modify data that isn't yours, don't degrade service, and don't test on real user accounts — use your own.
Machine-readable
Our security.txt follows RFC 9116.