← Back

Security & Vulnerability Disclosure

This page is for security researchers interested in reporting application security vulnerabilities found in Signet Protocol. It is intended for application security vulnerabilities only. Signet Protocol works collaboratively with researchers, Cyber Emergency Response Teams (CERTs), and asset owners to address cybersecurity vulnerabilities affecting our products, software, systems and infrastructure.

Typical vulnerabilities accepted

  • OWASP Top 10 vulnerability categories
  • Other vulnerabilities with demonstrated impact

Typical out of scope

  • Low-impact session management issues
  • Theoretical vulnerabilities
  • Informational disclosure of non-sensitive data
  • Self-XSS (user-defined payload)

Vulnerability disclosure guidelines

  • Provide a detailed description and proof of concept to enable reproduction of the vulnerability.
  • Do not engage in disruptive testing, such as denial-of-service attacks, or any activity that could impact the confidentiality, integrity or availability of systems or information.
  • Do not engage in social engineering or phishing of customers or employees.
  • Compensation is discretionary and may be provided by Signet Protocol where deemed appropriate.

How to report

Email contact@signet-protocol.com. See our security.txt file for the machine-readable version of this contact.

We use essential cookies to run this site, and optional analytics cookies to understand how it is used. Analytics only run if you accept them. Learn more.