Apartchain Security Policy
The security of the platform, digital assets and user data is a priority for us. If you discover a vulnerability in an Apartchain system, report it confidentially and give us reasonable time to investigate and remediate it.
Effective August 4, 2026
Report a vulnerability
Send your report to the address below. Do not publish vulnerability details or share them with third parties until the issue is remediated or disclosure is coordinated with Apartchain.
hello@apartchain.orgUse “SECURITY” in the subject line. Never send private keys, seed phrases, passwords or real personal data.
What to include
- A concise description of the issue and affected component.
- Exact reproduction steps, requests, transactions or a minimal proof of concept.
- Your assessment of the impact on users, data, tokens or funds.
- Your contact details and, if needed, the preferred way to coordinate disclosure.
Scope
This policy applies only to systems operated by Apartchain:
- apartchain.org
- Apartchain web application and public APIs
- The current Apartchain production program on Solana
Safe research rules
- Use only accounts, wallets, tokens and test data that you own.
- Stop immediately if you encounter personal, confidential or third-party data and notify us.
- Do not move funds or tokens, alter third-party records or submit destructive on-chain transactions.
- DoS/DDoS, high-volume scanning, brute force, spam, social engineering and physical attacks are prohibited.
- Do not use a vulnerability for extortion or disclose it publicly before a reasonable remediation period.
What happens next
We aim to acknowledge a report within five business days. Remediation priority and timing depend on demonstrated impact, reproducibility and exploitability. We may request additional information and will coordinate safe disclosure of a confirmed issue.
No public bug bounty program is currently offered. Submitting a report does not by itself create an entitlement to a monetary reward.