Security
Satora takes the security of our systems and your funds seriously. We appreciate the security community's help in keeping our platform safe.
Reporting a Vulnerability
If you discover a security vulnerability in Satora, please report it to us privately so we can address it before public disclosure. Do not report security issues via public GitHub issues, Telegram, or Twitter.
Disclosure Timeline
We aim to respond to all vulnerability reports within 24 hours and will work with you to understand the scope and severity of the issue. Our typical disclosure timeline:
Scope
We are interested in vulnerabilities affecting:
- satora.io and its subdomains
- Satora API endpoints
- Satora smart contracts
- Satora mobile applications
- Satora SDK packages
Safe Harbor
We consider security research conducted in good faith to be protected under safe harbor. This means:
- You will not face legal action from Satora for vulnerability research conducted in accordance with this policy.
- We will not forward your personal data to law enforcement unless you violate applicable law.
- We ask that you make a good faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services.
- Please only interact with accounts you own or have explicit permission to test.
Out of Scope
The following are considered out of scope:
- Rate limiting or brute force protection bypasses
- Missing security headers that do not impact security directly
- Self-XSS or issues requiring unlikely user interactions
- Social engineering attacks
- Physical attacks or physical security issues
- Presence of autofill / password manager attributes in forms
- TLS/SSL configuration issues
- Email SPF/DKIM/DMARC configuration issues
Contact
Email: security@satora.io
PGP Key: /.well-known/security.asc