Security.
How assets, keys and systems are protected, and how to report a vulnerability.
Controls
[Custodian] holds the underlying in accounts segregated from the issuer and from CenterNetwork.
Legal structure[Key management scheme and signer policy]; no single person can move reserves or mint tokens.
Security[Monitoring provider] watches reserve, mint and access events with on-chain alerts.
SecurityTwo audits before minting, on-chain and off-chain, and a new on-chain audit on every contract change.
AuditsDetection, containment, disclosure within [disclosure period] and a post-incident report.
Incident policy[Status page address]; uptime for the app, the explorer and the data feeds over 90 days.
StatusBug bounty
| Severity | Scope | Reward range |
|---|---|---|
| Critical | Loss or freeze of reserves, unauthorized minting | [Reward range] |
| High | Access control bypass, oracle manipulation | [Reward range] |
| Medium | Griefing, denial of service on contracts or app | [Reward range] |
| Low | Information disclosure without financial impact | [Reward range] |
Scope, exclusions and payment terms: [bounty policy document]
Responsible disclosure
Report vulnerabilities to [email protected]. Encrypt with the PGP key below; we acknowledge reports within [acknowledgement period] and keep you informed until the issue is resolved.
[PGP public key block to be published]
Fingerprint: [fingerprint]