# Security policy disorderly is built to be checked, not trusted. If you find a way to break it, we want to hear from you before anyone else does. This is how. ## Report a vulnerability - **Email:** security@disorderly.ai - Please include: what you found, where, and enough to reproduce it (a proof of concept, a transaction hash on testnet, or a short script). One issue per report is easiest to act on. - We aim to acknowledge within **72 hours** and to keep you updated as we triage and fix. - Please give us a reasonable window to fix before public disclosure. We will agree a timeline with you and credit you (or keep you anonymous) as you prefer. ## Safe harbor Good-faith security research conducted under this policy is authorized, and we will not pursue or support legal action against you for it. "Good faith" means: - Only test assets in scope (below), and only accounts/wallets you control. - Do not access, modify, or exfiltrate other people's data or funds. If you come across someone else's data, stop and report it. - No denial of service, spam, social engineering of our team or users, or physical attacks. Do not degrade the service for others. - Do not exploit beyond the minimum needed to prove the issue, and do not hold funds or data hostage. If you are unsure whether something is allowed, ask first at the address above. ## Scope **In scope:** - The smart contracts: `Disorderly721`, `PayoutDistributor`, `ProposalRegistry`, `RoyaltyRouter` (source in `contracts/`; verify deployed bytecode on Etherscan per [docs/VERIFY.md](docs/VERIFY.md)). - The mint flow and the mint page (`mint.html` + `mint/config.json` + the pinned-address check) - see [docs/MINT-SECURITY.md](docs/MINT-SECURITY.md). - disorderly.ai and its API (the site, the dashboard, the governance endpoints). - The payout/claim path and the published Merkle roots and records. **Out of scope:** - Third-party infrastructure we do not control: Cloudflare, DigitalOcean, the Ethereum L1, public RPC providers, and the external ERC-8004/8257 registries. - Anything requiring a compromised user device, browser extension, or a stolen private key. - Best-practice reports with no demonstrated impact (missing headers, version banners) unless chained into something exploitable. - Volatility of the NFT, or economic/governance outcomes that are working as designed. ## What we care about most In rough order of severity: 1. **Money moving wrong:** minting outside the allowlist or caps, forging or replaying a claim against `PayoutDistributor`, redirecting a payout, or draining any contract. 2. **Falsifying the record:** making the published payout/vote record disagree with what is anchored on chain in a way a holder could not detect. 3. **Mint redirection:** getting a user to send mint funds to an address that is not the published contract (site or config compromise, phishing paths we can mitigate). 4. **Governance integrity:** casting or altering a binding council ballot you are not authorized to, or bypassing the human veto on an irreversible action. 5. **Account/data:** unauthorized access to another holder's session, or writing to server state over HTTP. ## Rewards We pay discretionary rewards for valid, in-scope findings, scaled to severity and impact. This is a good-faith program run by a small team, not a fixed bounty table; we will be fair and transparent about how we assess a report. Duplicate reports are rewarded to the first clear, reproducible submission. Before mainnet, watch for a time-boxed **public break-in challenge** on the live Sepolia deployment with named targets and fixed rewards - see [docs/BREAK-IN-CHALLENGE.md](docs/BREAK-IN-CHALLENGE.md).