Version: 1.0 Last Updated: May 15, 2025
At Coinmerce, we take the security of our systems, products, and services seriously. We value the contributions of security researchers and the broader security community in helping us maintain a high level of security.
This Coordinated Vulnerability Disclosure (CVD) policy outlines how we wish to work with you to identify and resolve potential vulnerabilities. We are committed to a transparent and collaborative approach to vulnerability reporting.
The aim of this CVD policy is to ensure that vulnerabilities are identified, reported, and remediated in a coordinated manner, minimizing risk to our users, data, and services.
This policy applies to vulnerabilities found in the following Coinmerce owned/managed systems, products, and services:
If you are unsure whether a system or product is in scope, please contact us at [email protected] before starting any research.
If you believe you have discovered a vulnerability, please report it to us as soon as possible by:
When reporting, please include sufficient information to help us understand, reproduce, and address the vulnerability. This typically includes:
We ask that you act responsibly and in good faith when researching and reporting vulnerabilities:
Clear and timely communication is essential for a successful CVD process.
If you have any questions about this policy or the CVD process, please contact us at [email protected].