Skip to content

Security: useprovance/provance-client

Security

SECURITY.md

Security Policy

Provance handles real money. We take security seriously and we want to know about problems before they affect users.

Reporting a vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Email us at security@provance.xyz with:

  • A description of the vulnerability
  • Steps to reproduce it
  • What you think the impact is

We will respond within 48 hours and keep you updated as we work on a fix.

Scope

The things we care most about:

  • The Soroban savings vault contract (provance-contracts)
  • Anything that could allow funds to be moved without the depositor's authorisation
  • Key management and wallet handling

What we ask

Please give us time to fix the issue before disclosing it publicly. We will credit you if you want.

There aren't any published security advisories