Security

Satora takes the security of our systems and your funds seriously. We appreciate the security community's help in keeping our platform safe.

Reporting a Vulnerability

If you discover a security vulnerability in Satora, please report it to us privately so we can address it before public disclosure. Do not report security issues via public GitHub issues, Telegram, or Twitter.

Disclosure Timeline

We aim to respond to all vulnerability reports within 24 hours and will work with you to understand the scope and severity of the issue. Our typical disclosure timeline:

1. Acknowledgment
We confirm receipt within 24 hours.
2. Triage
We assess the report and determine severity within 3 business days.
3. Resolution
We develop and test a fix. Timeline depends on severity.
4. Release
We deploy the fix and notify you when it is live.
5. Disclosure
We coordinate public disclosure after the fix is deployed.

Scope

We are interested in vulnerabilities affecting:

Safe Harbor

We consider security research conducted in good faith to be protected under safe harbor. This means:

Out of Scope

The following are considered out of scope:

Contact