Skip to content

Security: aoxc/aoxchain

SECURITY.md

Security Policy

Reporting

Do not disclose suspected vulnerabilities in public issue trackers.

Report security findings privately to: security@aoxchain.io.

Include, at minimum:

  • affected component(s),
  • reproduction procedure or proof-of-concept,
  • impact statement (safety, funds, availability, integrity),
  • suggested mitigations if available.

Response objectives

  • Acknowledge receipt within 24 hours.
  • Perform technical triage and severity assignment.
  • Coordinate mitigation and release strategy based on impact class.
  • Publish advisory notes after risk containment.

Priority areas

  • Consensus safety/liveness violations.
  • State transition determinism failures.
  • Signature/key lifecycle vulnerabilities.
  • RPC/network abuse pathways.
  • Privilege-escalation or persistence boundary bypasses.

Operational security posture

Security assurance in AOXChain is evidence-driven and iterative. No absolute security guarantee is made.

License and liability context

This repository is provided under MIT on an "as is" basis, without warranties or liability assumptions by maintainers or contributors.

There aren’t any published security advisories