Security & Responsible Disclosure
How to report vulnerabilities and our commitments to security researchers acting in good faith.
How to report vulnerabilities and our commitments to security researchers acting in good faith.
VigilChain takes the security of our platform and the data entrusted to us seriously. We welcome responsible disclosure from security researchers and the broader community. If you believe you have discovered a security vulnerability in any VigilChain system, we encourage you to tell us about it so we can address it promptly.
This policy describes what is in scope for security research, how to report findings, what we ask of researchers, and our safe harbor commitments to researchers who act in good faith.
VigilChain will not pursue civil or criminal action against security researchers who discover and report vulnerabilities in accordance with this policy. We consider security research conducted under this policy to be authorized activity and will not treat it as a violation of our Terms of Service.
Specifically, to the extent that your activities are consistent with this policy, we will:
If legal action is initiated by a third party against you in connection with research conducted under this policy, we will take reasonable steps to make known that your activities were conducted in compliance with this policy.
Important: Safe harbor applies only to security research that complies with this policy. Activities that are clearly outside the scope of good-faith security research — such as accessing, exfiltrating, or destroying customer data; conducting denial-of-service attacks; or using vulnerabilities to attack other parties — are not covered.
The following systems are in scope for security research:
The following are explicitly out of scope:
Please email your findings to security@vigilchain.com. We ask that you:
If you believe the vulnerability is particularly sensitive, you may request our PGP key before submitting.
After you submit a report, you can expect the following:
We handle all reports confidentially. We ask that you do not publicly disclose the vulnerability until we have had adequate time to investigate and remediate, and that you coordinate any disclosure timing with us.
We assess reported vulnerabilities using CVSS v3.1 as a baseline, adjusted for deployment context. Critical and high severity findings are escalated immediately to our engineering team. All confirmed vulnerabilities receive a fix commitment with target remediation timelines communicated to the reporter.
For security vulnerability reports: security@vigilchain.com
For general security questions or inquiries unrelated to vulnerability disclosure, please use the same address.