Skip to content

Security: devkayazumi/splitstellar

Security

SECURITY.md

Security Policy

SplitStellar is non-custodial by default. It must not collect secret keys, mnemonic phrases, or custody credentials.

Reporting A Vulnerability

Do not open public issues for sensitive security reports. Contact maintainers privately with reproduction steps, impact, and suggested fixes when available.

Security Boundaries

  • No private-key handling.
  • No transaction signing in the app.
  • No custody of funds.
  • Settlement links must show destination wallet, memo, amount, asset, and network.
  • SEP-7 links must be generated from validated Stellar public keys.
  • Future Soroban work should focus on receipt attestations and group settlement proofs, not escrow.

There aren't any published security advisories