| Version | Support Status |
|---|---|
| 1.x.x | โ Supported |
| < 1.0 | โ Unsupported |
If you believe you've found a security vulnerability in Karibu, please contact us immediately.
DO NOT disclose the vulnerability publicly.
Email: Abdullahiabdi1233@gmail.com
We take all security reports seriously and will respond as quickly as possible.
- Keep your API keys secure and never share them
- Test smart contracts thoroughly on testnet before deployment
- Keep your browser updated
- Verify contract addresses before interaction
After submitting your report, here's our response timeline:
| Timeframe | Action |
|---|---|
| 48 hours | Acknowledgment of your report |
| 7 days | Initial assessment and validation |
| 30 days | Target timeline for fix release (varies based on complexity) |
We are committed to keeping you informed throughout this process with regular updates on our progress.
- Never share your Gemini API key or include it in client-side code
- Store your
.env.localfile securely and never commit it to public repositories - Implement a regular schedule for API key rotation
- Always review the security analysis provided by Karibu before deployment
- Test contracts thoroughly on testnet before considering mainnet deployment
- Follow standard smart contract security best practices:
- โ Check for reentrancy vulnerabilities
- โ Validate all inputs
- โ Handle edge cases in arithmetic operations
- โ Implement proper access controls
- Keep your browser updated to the latest version
- Be cautious when interacting with third-party contracts
- Always verify contract addresses before interaction
Karibu includes several built-in security features to protect users:
| Feature | Description |
|---|---|
| Contract Analysis | Automated security checks scan for common vulnerabilities |
| Testnet-Only Operations | All deployments are limited to supported Testnets |
| No Wallet Requirements | No private keys are required from users |
| Server-Side Signing | All blockchain transactions are signed server-side |
We are continuously improving our security practices:
| Timeline | Feature |
|---|---|
| Q2 2025 | Enhanced security analysis integration |
| Ongoing | Advanced vulnerability detection for complex contract patterns |
| Ongoing | Integration with industry security standards |
For any security-related questions or concerns not covered here, please contact us at Abdullahiabdi1233@gmail.com