Skip to content

Latest commit

 

History

History
32 lines (21 loc) · 1.03 KB

File metadata and controls

32 lines (21 loc) · 1.03 KB

Security Policy

Sluice moves money. We take security seriously and welcome responsible disclosure.

Status

SluiceStream is an unaudited reference implementation. It is not deployed to mainnet and must not hold real funds until an independent audit is complete. Treat everything in contracts/ as pre-audit until a report is linked here.

Supported versions

Version Supported
0.2.x
0.1.x ⚠️ security fixes only
< 0.1

Reporting a vulnerability

Please do not open a public issue for security problems.

  • Email: security@getsluice.xyz
  • Include: affected file/function, a description, and a proof-of-concept if possible.

We aim to acknowledge within 48 hours and to ship a fix or mitigation for confirmed, in-scope issues. A post-audit bug-bounty scope will be published before mainnet.

Scope

In scope: the contracts under contracts/, the SDK under sdk/, and anything that could cause loss of funds, incorrect accrual, or a stuck/undrainable balance.