Responsible Disclosure Policy

Last updated: 2026

1. Reporting a Vulnerability

If you discover a security vulnerability in CreateSolana, please report it responsibly to security@createsolana.com. Include:

  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce (proof-of-concept if possible).
  • Your contact information for follow-up.

2. Safe Harbor

We will not take legal action against researchers who:

  • Report vulnerabilities in good faith.
  • Avoid accessing, modifying, or destroying user data.
  • Do not exploit the vulnerability for profit or to harm users.
  • Give us reasonable time to fix the issue before public disclosure.

3. Scope

This policy covers the CreateSolana web application at the official domain:

  • Frontend code (Next.js app, components, libraries).
  • Transaction construction and signing flows.
  • RPC and storage integrations (Helius, Chainstack, Arweave/Irys).
  • Authentication and wallet connection flows.

Out of scope:

  • Vulnerabilities in third-party programs (SPL Token, Token-2022, Metaplex, pump.fun) — report to their maintainers.
  • Denial-of-service via high-volume automated requests.
  • Social engineering attacks against our team.

4. Response Time

We acknowledge receipt of reports within 48 hours and aim to provide a substantive response within 5 business days. Critical issues are prioritized.

5. Rewards

We may offer rewards for valid reports at our discretion, depending on severity and impact. Rewards are not guaranteed and are evaluated on a case-by-case basis.

6. Public Disclosure

Please do not publicly disclose a vulnerability until we have released a fix and given explicit permission. We credit researchers in our security advisories when desired.

7. Contact

For security questions, contact security@createsolana.com. See also our security.txt.