← AssetFare

Security and private reporting

AssetFare never receives private keys and never signs or submits a transaction. Report an unpatched vulnerability privately; do not post secrets or exploit details in a public issue.

Report privately

Email security@assetfare.dev or use the GitHub private vulnerability reporting form. Include affected URLs or versions, impact, reproduction steps, and a minimal proof of concept.

Never include a private key, seed phrase, bearer token, signed transaction, or personal data. Revoke or rotate any credential that may have been exposed and provide only a redacted identifier.

Safe testing boundaries

Publishing security.txt does not grant authorization to test systems or funds.

Scope and response

Reports may cover the public route API, remote MCP compatibility adapter, machine-readable discovery artifacts, and caller-signed workflow. AssetFare does not currently operate a bug-bounty program or promise a response time during capped demand validation. Good-faith reports will be reviewed as operational capacity permits.

Non-sensitive support

Email support@assetfare.dev or use public GitHub issues only for non-sensitive product defects and documentation questions.