Security Policy
July 30, 2026 ยท View on GitHub
Supported Versions
We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:
| CVSS v3.0 | Supported Versions |
|---|---|
| 9.0-10.0 | Releases within the previous three months |
| 4.0-8.9 | Most recent release |
Reporting a Vulnerability
Please report suspected security vulnerabilities confidentially through the Fireblocks bug bounty program on Bugcrowd. We ask that you refrain from opening GitHub issues pertaining to possible security issues.
Before submitting, please read SECURITY-MODEL.md for the threat model, integrator contract, and scope of the bounty. Researchers and AI-assisted analysis pipelines should also consult CLAUDE.md.
For anything that is not security related, please consult our contribution guidelines.
Security Audits
The code has been audited by NCC.