We actively support security updates for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ Active |
| 0.x.x | ❌ Not Supported |
We take security seriously and appreciate your efforts to disclose vulnerabilities responsibly.
- Cross-site scripting (XSS) attacks
- Cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- Authentication and authorization issues
- Mobile platform-specific vulnerabilities (Android/iOS)
- Web application security issues
- Flutter/Dart specific security concerns
- Denial of Service (DoS) attacks
- Social engineering attacks
- Physical security issues
- Known vulnerabilities with public exploits
- Theoretical vulnerabilities without proof-of-concept
For minor security issues, please open a Security Issue using our security template.
For sensitive vulnerabilities, please contact our security team privately:
Email: security@rechain.vc
PGP Key: [Available upon request]
Encrypted Email: Use ProtonMail for sensitive disclosures
- Acknowledgment: Within 48 hours
- Assessment: Within 5 business days
- Resolution: Within 30 days for critical issues
- Disclosure: Coordinated disclosure after patch is available
- Report: Submit vulnerability details privately
- Triage: Security team assesses impact and validity
- Fix: Develop and test patch
- Release: Deploy fix to supported versions
- Disclosure: Publish security advisory with CVE (if applicable)
- Credit: Acknowledge reporter in release notes
- Code Analysis: Flutter analyze, Dart linting
- Dependency Scanning: pub deps, dependabot
- Static Analysis: Trivy, CodeQL
- Runtime Security: Flutter secure coding practices
We follow responsible disclosure principles:
- No public disclosure before patch availability
- Credit to researchers in release notes
- Coordination with CVE assignment
- No legal action against good-faith researchers
We offer a bug bounty program for eligible vulnerabilities:
- Low: $100 USD
- Medium: $500 USD
- High: $1,000 USD
- Critical: $2,500+ USD
See our Bug Bounty Program for details.
Security reports should adhere to our Code of Conduct. Malicious or unethical behavior will not be tolerated.
For questions about our security policy, contact security@rechain.vc.
Last updated: September 2024