Skip to content

Security: Miny-Labs/sortes

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you discover a security vulnerability in Sortes, please do not open a public issue. Instead, email the maintainers privately:

We will acknowledge receipt within 72 hours and provide a remediation timeline within 7 days. Critical vulnerabilities may be fast-tracked.

Scope

In scope:

  • Sortes-specific contracts under src/ (ConfidentialCollateralWrapper, SealedPool, SortesMarketFactory, oracle bridge contracts).
  • Sortes-specific deployment scripts under script/.

Out of scope (report to upstream maintainers):

Audit history

Sortes is pre-audit. The novel contracts (ConfidentialCollateralWrapper, SealedPool) are intended for ChainSecurity or Trail of Bits review prior to mainnet launch. Audited upstream components retain their original audit perimeter:

Bug bounty

A formal bug bounty will be opened post-mainnet launch. Pre-launch disclosures are credited in the security acknowledgments section of the README and may be eligible for retroactive rewards from the protocol treasury.

There aren't any published security advisories