Contact: mailto:security@aere.network Contact: https://aere.network/security Expires: 2027-06-01T00:00:00.000Z Preferred-Languages: en Canonical: https://aere.network/.well-known/security.txt Policy: https://aere.network/security # AERE Network, security disclosure policy # # We accept good-faith vulnerability reports for: # - The AERE chain (chain ID 2800) consensus, RPC, and node infrastructure # - All Solidity contracts deployed by the Foundation (see /docs.html registry) # - The Foundation-operated relayer and watcher services (aere.network/relay/, /bridge-api/) # - The aere.network website and SDK (@aere/sdk) # # Out of scope: # - User-deployed dApps on AERE # - Third-party Hyperlane / Across / SP1 / RISC Zero infrastructure # # We do NOT currently offer a paid bug bounty. We commit to: # - Acknowledging reports within 72 hours # - Coordinating disclosure with reporter # - Public credit on AUDITS.md unless the reporter requests anonymity # # Critical issues (loss of funds, loss of signing control, chain halt) should be reported # via email AND a private notice to the founder via known channels.