The Geek Protocol team takes security seriously. We appreciate your efforts to responsibly disclose your findings.
If you discover a security vulnerability, please report it to us through one of the following methods:
- Private Disclosure: Open a GitHub Security Advisory
- Direct Contact: Message the team on Telegram (request private conversation with admins)
- Email: Contact us through our official channels (link in repository)
When reporting a vulnerability, please include:
- Description: Clear description of the vulnerability
- Impact: Potential impact and attack scenarios
- Steps to Reproduce: Detailed steps to reproduce the issue
- Proof of Concept: If applicable, include PoC code or screenshots
- Suggested Fix: If you have ideas on how to fix it
- Your Contact Info: So we can follow up with questions
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
- Updates: We will provide regular updates on our progress (at least every 7 days)
- Timeline: We aim to patch critical vulnerabilities within 7 days
- Credit: With your permission, we will credit you in our security advisories
To protect our users, we ask that you:
- β DO: Report the vulnerability privately before public disclosure
- β DO: Give us reasonable time to fix the issue before going public
- β DO: Act in good faith and avoid privacy violations or data destruction
- β DON'T: Publicly disclose the vulnerability before we've had time to address it
- β DON'T: Exploit the vulnerability beyond what's necessary to demonstrate it
- β DON'T: Access or modify other users' data
- Regular dependency updates
- Code review process for all changes
- HTML validation and link checking on PRs
- Secure hosting on trusted platforms
When smart contracts are deployed:
- Multiple independent security audits
- Bug bounty program
- Gradual rollout with monitoring
- Emergency pause mechanisms
| Version | Supported |
|---|---|
| Latest | β Yes |
| Older | β No |
We only support the latest version of our documentation and website. Always use the latest version from the main branch.
This repository currently contains documentation only. As we move into development phases with smart contracts and backend systems, this policy will be updated with specific security considerations for:
- Smart contract vulnerabilities
- API security
- Database security
- User authentication and authorization
- Token security
We thank the following security researchers for their responsible disclosure:
- None reported yet
For general security questions or concerns:
- Join our Telegram Community
- Follow us on X/Twitter
Remember: Security is everyone's responsibility. Thank you for helping keep Geek Protocol and our community safe!