Responsible disclosure
If you find a vulnerability in the Unvault app, APIs, or the protocol contracts, tell us privately at security@unvault.com or through the Report Bug button in the app. Include steps to reproduce, the affected chain and contract address if relevant, and how to reach you.
What we ask: do not exploit the issue, do not access other users' data or assets, and give us reasonable time to fix it before disclosing publicly. Exploiting a bug for gain is a violation of the Terms of Service (Section 16) and may be a crime.
What you can expect: an acknowledgement within three business days, updates as we work on it, credit if you want it, and a reward for significant findings at Unvault's discretion. Findings in protocol contracts are coordinated with UV Tech Foundation, which owns them.