Blockdaemon Vulnerability Disclosure Policy

Vulnerability Disclosure Program (VDP) Policy

Introduction

At Blockdaemon, we prioritize the security and privacy of our customers, partners, and systems. We recognize that responsible security research plays a crucial role in identifying and mitigating vulnerabilities before they can be exploited by malicious actors.

This Vulnerability Disclosure Program (VDP) provides guidelines for security researchers and ethical hackers to report security vulnerabilities in our systems safely, ensuring a collaborative and coordinated approach to improving security.

Scope

We encourage responsible reporting of vulnerabilities related to:

In-Scope Assets to be Tested

Out-of-Scope Assets

Safe Harbor Policy

We are committed to working with security researchers in good faith. If you comply with this policy and report vulnerabilities responsibly:

Reporting a Vulnerability

To report a security vulnerability, please email vdp@blockdaemon.com with:

Our Response Timeline

When you report a vulnerability, here’s what you can expect:

Vulnerability Classification & Severity

We use Common Vulnerability Scoring System (CVSS v3.1) to assess the severity of reported vulnerabilities.

Coordinated Disclosure Policy

Rewards & Recognition

Blockdaemon’s Vulnerability Disclosure Program (VDP) is not a bug bounty program, and no monetary rewards are offered. However, we welcome responsible vulnerability reports, offer safe harbor for ethical disclosures, and may recognize impactful contributions with public acknowledgment or swag.

Legal Considerations

By submitting a vulnerability report, you agree:

Acknowledgment

We sincerely thank the security community for helping protect the Blockdaemon ecosystem. Your responsible disclosures make a meaningful impact!