AssetFare never receives private keys and never signs or submits a transaction. Report an unpatched vulnerability privately; do not post secrets or exploit details in a public issue.
Email security@assetfare.dev or use the GitHub private vulnerability reporting form. Include affected URLs or versions, impact, reproduction steps, and a minimal proof of concept.
Never include a private key, seed phrase, bearer token, signed transaction, or personal data. Revoke or rotate any credential that may have been exposed and provide only a redacted identifier.
Publishing security.txt does not grant authorization to test systems or funds.
Reports may cover the public route API, remote MCP compatibility adapter, machine-readable discovery artifacts, and caller-signed workflow. AssetFare does not currently operate a bug-bounty program or promise a response time during capped demand validation. Good-faith reports will be reviewed as operational capacity permits.
Email support@assetfare.dev or use public GitHub issues only for non-sensitive product defects and documentation questions.