Skip to content

docs: add SECURITY.md — Phase 1 disclosure policy#21

Open
abhicris wants to merge 1 commit into
create-protocol:research/depin-benchmarkfrom
abhicris:docs/security-policy
Open

docs: add SECURITY.md — Phase 1 disclosure policy#21
abhicris wants to merge 1 commit into
create-protocol:research/depin-benchmarkfrom
abhicris:docs/security-policy

Conversation

@abhicris
Copy link
Copy Markdown
Member

@abhicris abhicris commented Jun 4, 2026

Summary

Add SECURITY.md to the repo root setting explicit disclosure expectations for the pre-audit Phase 1 period. No code changes.

What's in scope

  • Supported-versions table (testnet vs mainnet, audited vs not)
  • Reporting channel (security@kcolbchain.com) + PGP key reference
  • Bug-bounty posture: not yet active; signposted for Phase 2 once a real value-at-risk surface exists
  • Out-of-scope items: third-party libs, infra not run by Create Protocol, denial-of-service against testnet RPC
  • Response-timeline commitment (acknowledge in 72h, triage in 7 days)

Why

External researchers asking about disclosure now get a clear policy file instead of having to read README + commit history. Signals that the project takes security seriously even pre-audit, which matters for the Phase 1 → Phase 2 audit prep.

What's NOT in scope

  • No bug bounty payout structure (deferred to Phase 2)
  • No threat model document (separate docs/security/THREAT_MODEL.md PR will follow)
  • No formal disclosure timeline (90-day or otherwise) — left flexible for Phase 1

Pairs with the three already-merged spec PRs (#18, #19, #20) as part of the repo-quality sweep.

CR8 is pre-audit Phase 1. This SECURITY.md sets the disclosure expectation
explicitly so external researchers know:

- Phase boundaries (testnet vs mainnet, audited vs not)
- The reporting channel (security@kcolbchain.com) and PGP key reference
- Bug-bounty posture (not yet active; signposted for Phase 2)
- Out-of-scope items (third-party libs, infra not run by Create Protocol)
- Response timeline commitment

No code changes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant