TRUST / SECURITY
Security policy
Report reproducible vulnerabilities privately without exposing credentials or another person's data.
SECURITY POLICY · UPDATED 1 AUGUST 2026
Report vulnerabilities privately
Send a bounded report to contact@chain4663.com with the affected route or commit, impact, reproduction steps, and a safe proof of concept. Do not send passwords, provider tokens, session cookies, API keys, wallet secrets, private keys, seed phrases, or another person’s personal data.
Good-faith research
Use accounts and data you control, avoid destructive or high-volume testing, stop if you encounter another person’s data, and allow a reasonable remediation period before disclosure. Volumetric denial of service, social engineering, phishing, physical attacks, and testing third-party providers are outside scope.
Account boundary
The account release accepts only Google or GitHub OAuth at exact callbacks, retains a normalized verified email and bounded hash linkage, stores sessions and API keys hash-only, and sends no application email. Public reports should never include raw OAuth codes, state, nonce, verifier, cookies, or keys.
There is no paid bounty program or guaranteed reward. Good-faith, policy-compliant research will be evaluated proportionately. See security.txt for the machine-readable contact.