Responsible Disclosure Policy
Last updated: 2026
1. Reporting a Vulnerability
If you discover a security vulnerability in CreateSolana, please report it responsibly to security@createsolana.com. Include:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce (proof-of-concept if possible).
- Your contact information for follow-up.
2. Safe Harbor
We will not take legal action against researchers who:
- Report vulnerabilities in good faith.
- Avoid accessing, modifying, or destroying user data.
- Do not exploit the vulnerability for profit or to harm users.
- Give us reasonable time to fix the issue before public disclosure.
3. Scope
This policy covers the CreateSolana web application at the official domain:
- Frontend code (Next.js app, components, libraries).
- Transaction construction and signing flows.
- RPC and storage integrations (Helius, Chainstack, Arweave/Irys).
- Authentication and wallet connection flows.
Out of scope:
- Vulnerabilities in third-party programs (SPL Token, Token-2022, Metaplex, pump.fun) — report to their maintainers.
- Denial-of-service via high-volume automated requests.
- Social engineering attacks against our team.
4. Response Time
We acknowledge receipt of reports within 48 hours and aim to provide a substantive response within 5 business days. Critical issues are prioritized.
5. Rewards
We may offer rewards for valid reports at our discretion, depending on severity and impact. Rewards are not guaranteed and are evaluated on a case-by-case basis.
6. Public Disclosure
Please do not publicly disclose a vulnerability until we have released a fix and given explicit permission. We credit researchers in our security advisories when desired.
7. Contact
For security questions, contact security@createsolana.com. See also our security.txt.