Skip to content

Security: cyberdocs120/trustRent

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

trustRent handles real money. Please do not open a public GitHub issue for security vulnerabilities.

Email: security@trustrent.xyz
PGP Key: docs/security/pgp-key.asc

We aim to acknowledge reports within 24 hours and patch critical issues within 72 hours.

Scope

  • Smart contract logic (escrow, arbitration)
  • API authentication and authorization
  • Key handling and signing flows
  • Dependency vulnerabilities

Out of Scope

  • Issues in testnet-only deployments with no real funds
  • Social engineering attacks

There aren't any published security advisories