| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
To report a security vulnerability, do not open a public issue.
Email: security@trustchain-escrow.io
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge within 48 hours and provide a resolution timeline within 7 days.
- Smart contract logic (
contracts/) - Backend API (
backend/) - Authentication and authorisation flows
- Fund custody and release logic
- Social engineering attacks
- Issues in third-party dependencies (report upstream)
- Denial of service via resource exhaustion