We work with security researchers in good faith. If you find a vulnerability in Conto, this page tells you how to report it, what we will do in response, and what is in or out of scope.
Email security@conto.finance. Include reproduction steps, the affected URL or endpoint, the impact you believe the issue has, and any proof-of-concept code. Plain text is fine. We do not require encryption for the initial report; if you prefer encryption, ask for our PGP key in your first message and we will reply with it.
Please do not file public GitHub issues for suspected vulnerabilities. Please do not post details to social media or public forums until we have agreed on a coordinated disclosure date.
The machine-readable version of this policy is at /.well-known/security.txt per RFC 9116.
The following are in scope:
The following are out of scope:
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. We consider activity that follows this policy to be authorized, and we will work with you to understand and resolve the issue quickly.
To stay within safe harbor, please:
If you are unsure whether a planned test would fall within this policy, ask first at security@conto.finance.