We treat the security of customer accounts, balances, and personal data as a core operational requirement. If you believe you have found a vulnerability in a system we operate, we want to hear from you, and we will work with you to validate, remediate, and — where appropriate — publicly credit the finding.
Report security issues to security@safety-wallet.app. Please do not use public issue trackers, social media, or customer support channels to disclose unresolved vulnerabilities.
In scope
The following assets and functionality are in scope for testing under this policy.
- safety-wallet.app — the public marketing site and all authenticated application routes
- Authentication and session handling, including registration, login, password reset, recovery phrase flows, one-time codes, and multi-factor enrolment
- Wallet functionality, including deposit address derivation and assignment, balances, sends, swaps, staking, and fiat withdrawal requests
- Administrative and agent surfaces, including per-user permissions, role separation, impersonation controls, and audit logging
- Server actions and API routes, including authorisation checks, input validation, and database row-level security enforcement
- Support and ticketing workflows, including KYC document handling and transactional email delivery
Out of scope
The following activities and report categories are excluded. Submissions limited to these areas will be closed as out of scope, though we still appreciate being informed of anything that materially affects our customers.
- Social engineering, phishing, or pretexting directed at our staff, agents, customers, or vendors
- Physical attacks against our offices, personnel, or hardware
- Denial-of-service, volumetric load testing, brute-force, or resource-exhaustion testing against production systems
- Automated scanner output submitted without a demonstrated, exploitable impact
- Missing security headers, cookie flags, or TLS configuration findings with no proven exploit path
- Vulnerabilities affecting only unsupported browsers, rooted or jailbroken devices, or end-user machines already compromised by malware
- Reports that require a privileged position we did not grant, such as an existing administrator session or direct database access
- Findings in third-party services we do not operate; please report those to the relevant vendor
- Self-inflicted issues, including disclosure of your own recovery phrase, password, or one-time codes
How to report
Send a single email per issue to security@safety-wallet.app and include as much of the following as you can. Complete reports are triaged substantially faster.
- A clear description of the vulnerability and the security impact you believe it has
- The exact affected URL, route, server action, or component
- Step-by-step reproduction instructions, including any required account state or preconditions
- Supporting evidence such as request and response captures, a minimal proof-of-concept, or a short screen recording
- Any account identifiers or test email addresses you used, so we can correlate the activity in our logs
- Your assessment of severity and the attacker position the issue requires
Rules of engagement
Good-faith research means testing in a way that protects our customers. We ask that you observe the following conditions at all times.
- Use only accounts you own or accounts you have been explicitly authorised to test
- Limit testing to the minimum activity required to demonstrate the issue
- Never access, modify, exfiltrate, or retain data belonging to another person or entity
- Stop immediately and report to us if you encounter personal data, credentials, keys, or customer funds
- Do not move, spend, or attempt to withdraw funds that are not yours, even where a defect appears to permit it
- Do not degrade, disrupt, or reduce the availability or integrity of our production services
- Do not publish or share details of an unresolved issue with third parties without our written agreement
Our response commitments
We aim to keep researchers informed throughout the lifecycle of a report. Our target timelines are set out below and are measured from the point a report is received.
- Acknowledgement of your report
- Within 3 business days
- Initial triage and severity assessment
- Within 7 business days
- Remediation status update
- At least every 14 days until closure
- Coordinated public disclosure
- By mutual agreement after a fix is deployed
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not initiate or support legal action against you in relation to that research, and we will not report it to law enforcement. Should a third party bring action against you for activity conducted in accordance with this policy, we will make it known that your testing was authorised.
This authorisation does not extend to activity that breaches applicable law, accesses or retains data belonging to others, disrupts our production services, or falls outside the scope defined above. If you are unsure whether a specific test is permitted, contact us at security@safety-wallet.app before proceeding and we will respond with written guidance.
Disclosure and recognition
We ask that you give us a reasonable opportunity to remediate before disclosing an issue publicly, and that any coordinated disclosure be agreed with us in writing. Rewards are discretionary and are assessed case by case according to demonstrated impact, report quality, and originality; submitting a report does not guarantee a payment. With your permission, we are glad to credit you once a fix has shipped.
Machine-readable contact
Our RFC 9116 contact details are published at /.well-known/security.txt.
Last updated 27 August 2026. This policy may be revised at any time; the version published on this page governs research conducted under it.