Skip to content

Security: coinnect-dev/coinnect

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Coinnect, please report it responsibly:

Email: miguel@coinnect.bot

Subject line: [SECURITY] Brief description

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Assessment: within 7 days
  • Fix: as soon as possible, typically within 14 days for critical issues

Scope

This policy covers:

  • The Coinnect web application at coinnect.bot
  • The public REST API (/v1/*)
  • The source code at github.com/coinnect-dev/coinnect

Out of Scope

  • Rate accuracy (rates are informational and change constantly)
  • Third-party provider websites linked from Coinnect
  • Social engineering attacks

Recognition

We gratefully acknowledge security researchers who report vulnerabilities responsibly. With your permission, we will credit you in our changelog.

Security Contact

There aren’t any published security advisories