diff --git a/SECURITY.md b/SECURITY.md index d41c43a..2c8bbcf 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,9 +1,14 @@ -## How to Report a Security Bug +# Security Policy -TBD +All in Bits strives to contribute toward the security of our ecosystem through internal security practices, and by working with external security researchers from the community. -***Please DO NOT file a public issue in this repository to report a security vulnerability.*** +## Reporting a Vulnerability -## Coordinated Vulnerability Disclosure Policy and Safe Harbor +If you've identified a vulnerability, please report it through one of the following venues: +* Submit an advisory through GitHub: https://github.com/atomone-hub/govgen/security/advisories/new +* Email security [at-symbol] tedermint [dot] com. If you are concerned about confidentiality e.g. because of a high-severity issue, you may email us for PGP or Signal contact details. +* We provide bug bounty rewards through our program at [HackenProof](https://hackenproof.com/all-in-bits). You must report via HackenProof in order to be eligible for rewards. -TBD +We will respond within 3 business days to all received reports. + +Thank you for helping to keep our ecosystem safe!