Security Policy

July 30, 2026 ยท View on GitHub

Supported Versions

We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:

CVSS v3.0Supported Versions
9.0-10.0Releases within the previous three months
4.0-8.9Most recent release

Reporting a Vulnerability

Please report suspected security vulnerabilities confidentially through the Fireblocks bug bounty program on Bugcrowd. We ask that you refrain from opening GitHub issues pertaining to possible security issues.

Before submitting, please read SECURITY-MODEL.md for the threat model, integrator contract, and scope of the bounty. Researchers and AI-assisted analysis pipelines should also consult CLAUDE.md.

For anything that is not security related, please consult our contribution guidelines.

Security Audits

The code has been audited by NCC.