Skip to content
This repository was archived by the owner on Feb 16, 2026. It is now read-only.

Security: intent-solutions-io/irsb-protocol

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x (Sepolia) Yes
< 1.0 No

Reporting a Vulnerability

Please do NOT open public GitHub issues for security vulnerabilities.

How to Report

Email: jeremy@intentsolutions.io

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

Timeline Action
48 hours Acknowledgment of report
7 days Initial assessment
30 days Fix timeline communicated
90 days Public disclosure (coordinated)

Scope

In scope:

  • Smart contracts (src/)
  • Deployment scripts (script/)
  • SDK (sdk/)
  • Subgraph (subgraph/)

Out of scope:

  • Third-party dependencies (report upstream)
  • Dashboard UI-only issues
  • Already known issues in GitHub Issues

Safe Harbor

We will not pursue legal action against researchers who:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Do not exploit vulnerabilities beyond proof-of-concept
  • Report findings promptly and confidentially

Bug Bounty

No formal bug bounty program exists yet. Significant findings may be rewarded at maintainer discretion.

Security Contacts

There aren’t any published security advisories