Skip to content

Security: Multyr/multyr-core

Security

SECURITY.md

Security Policy

Supported Versions

The latest tagged release on main is supported. Older tags receive fixes only for critical issues at the Multyr Foundation's discretion.

Reporting an Issue

Please email security@multyr.fi with:

  • A summary of the issue
  • Steps to reproduce (if applicable)
  • Affected commit hash or version tag
  • Your suggested mitigation (optional)

Do not open public issues for sensitive matters. Wait for our acknowledgement before any public discussion.

Response Timeline

  • Acknowledgement of receipt: within 72 hours
  • Triage and severity assessment: within 7 days
  • Coordinated disclosure window: typically 90 days, adjustable per case

Rewards

A formal rewards program is not yet active. The Multyr Foundation may offer discretionary rewards for high-impact reports at its sole discretion.

Out of Scope

  • Issues in third-party dependencies (report upstream)
  • Issues in testnet deployments unless they indicate a mainnet risk
  • Social engineering, phishing, or physical access scenarios
  • Denial of service against the Foundation's web infrastructure

There aren't any published security advisories