Skip to content

Security: PactVerityHQ/pactverity

Security

SECURITY.md

Security policy

Reporting a vulnerability

Send non-public vulnerability reports to contact@pactverity.com with the subject Security report. Include the affected component, tested revision, reproduction steps, expected impact and any suggested mitigation.

Do not publish exploitable details before coordinated remediation. Never send seed phrases, private keys, passwords, wallet approvals, customer data or unrelated personal information.

Public methodology questions that do not expose a vulnerability may be raised through the repository review issue.

Current assurance boundary

PactVerity publishes internal tests, known-answer checks and an independent review scope. These are not a completed independent audit. No value-bearing PactVerity Solana program is represented as audited or production-ready.

Current status and review documents are published at:

There aren't any published security advisories