We take the security of Stellar-IndigoPay seriously. If you discover a security vulnerability, please report it to us responsibly.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please use one of the following methods:
- Send a private disclosure email to our security team.
- Use GitHub Security Advisories to privately report a vulnerability to the maintainers of this repository.
We are committed to resolving security issues promptly. Our response SLA is as follows:
- Acknowledgement: We will acknowledge receipt of your vulnerability report within 48 hours.
- Patch/Resolution: For critical vulnerabilities, we aim to provide a patch or mitigation within 30 days.
The following issues are currently considered out of scope for our security response:
- Issues or vulnerabilities that are strictly applicable to testnet-only environments.
- Rate limiting bypasses that do not demonstrate a tangible, real-world security impact.
- Volumetric or application-level Denial of Service (DoS) attacks.
- Social engineering or phishing attacks.
At this time, we do not have an active, paid bug bounty program. However, we deeply appreciate community contributions and will gladly provide public acknowledgment or credit to security researchers who responsibly disclose valid vulnerabilities.