walras

Security Policy — walras

Reporting a vulnerability

Report privately by email to kunaldrall29@gmail.com. Do not open a public issue for an undisclosed vulnerability. You will receive an acknowledgement within 7 days of your report.

There is no bug bounty at this time. That is stated plainly so nobody invests effort expecting one; reports are still wanted and will be credited if you ask.

Status: testnet, unaudited

Everything this repository describes runs on stellar:testnet, and the code is unaudited. A third-party security review via the Stellar Audit Bank is planned before any mainnet production tag; the audit scope — an offchain service and its cryptographic validation, no new Soroban contract in v1 — is stated in docs/THREAT-MODEL.md §4.

In scope

The threat inventory lives in docs/THREAT-MODEL.md; reports against any row there, or against a threat it misses, are in scope. Specifically:

Out of scope

Secrets hygiene for reporters

Never include a real secret seed (S...) in a report — not even a testnet seed you consider disposable. Testnet reproduction cases are welcome: transcripts, payment payloads, transaction hashes, and public addresses are all safe to send and make reports far easier to act on.