Skip to content

draft: bug bounty policy (owner to fill) - #10

Draft
SaulBuilds wants to merge 1 commit into
mainfrom
draft/bug-bounty-policy
Draft

SaulBuilds wants to merge 1 commit into
mainfrom
draft/bug-bounty-policy

Conversation

@SaulBuilds

Copy link
Copy Markdown
Contributor

Draft bug bounty policy, split out of #7 so #7 can merge now. Do not merge until the owner fills it in and counsel signs off.

BOUNTY.md is marked "DRAFT, not in force". It covers:

  • scope: testnet 40204 and in-scope assets
  • surfaces that are not deployed or not running (product status only)
  • safe harbor
  • load limits for shared hosts
  • a Known issues placeholder, published per finding once fixed

OWNER TO FILL:

  • reward amounts per severity
  • launch date, payout method and currency, KYC for payout, eligibility
  • a PGP key for security@citrate.ai
  • confirm or change the proposed host limits (5 req/s and 10,000 req/day per host)
  • counsel review of the safe-harbor text

After merging:

  • link BOUNTY.md from SECURITY.md, replacing "Bounty policy: coming soon"
  • remove the "not in force" banner

Checks:

Tracking: CitrateNetwork/citrate-security#87.

🤖 Generated with Claude Code

https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FYQkdsk54yob6FD24jAT8P
@SaulBuilds
SaulBuilds force-pushed the draft/bug-bounty-policy branch from e7f2017 to 265de58 Compare September 27, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant