Skip to content

docs: complete SECURITY.md with scope, disclosure timeline, and bug bounty#1

Open
devSoniia wants to merge 1 commit into
mainfrom
feat/security-policy-64
Open

docs: complete SECURITY.md with scope, disclosure timeline, and bug bounty#1
devSoniia wants to merge 1 commit into
mainfrom
feat/security-policy-64

Conversation

@devSoniia
Copy link
Copy Markdown
Owner

Summary

Completes SECURITY.md to satisfy all acceptance criteria for Vera3289#64.

Changes

  • Scope — lists in-scope contracts and vulnerability classes
  • Out of scope — explicit list of what is not eligible for bounty
  • Disclosure timeline — table with milestones and target windows (ack 48h, triage 5 days, patch 30/90 days)
  • Bug bounty — severity tiers (Critical/High/Medium/Low) with USDC reward amounts
  • Retains existing audit table, supported versions, and security design notes
  • Cross-references docs/security/threat-model.md and audits/remediation.md

Checklist

  • SECURITY.md covers all required sections
  • Contact email present (security@paystream.example)
  • Bug bounty scope defined
  • Disclosure timeline documented

Closes Vera3289#64

…ounty

- Add in-scope / out-of-scope sections
- Add coordinated disclosure timeline table
- Add bug bounty programme with severity/reward tiers
- Retain existing audit table and security design notes
- Reference threat-model.md and remediation.md

Closes Vera3289#64
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add SECURITY.md with responsible disclosure process

1 participant