Bug Bounty Program

We welcome responsible security research. Reports are reviewed on a case-by-case basis and valid findings may be rewarded.

Version: 0.1-Beta·September 2026

Table of Contents

01Program Overview
02Scope and Eligible Assets
03Eligibility Requirements
04Ticket Quality Expectations
05Out of Scope
06Reward Policy
07Submission Process

01 · Program Overview

Cornicular is committed to maintaining the highest security standards for our blockchain-based document verification platform. At this time, we do not run a formal bug bounty program with published reward tiers.

However, we still welcome responsible security research. If you find a valid vulnerability in our systems, please report it to us. If our team verifies the finding as valid, we may still provide a reward, with the amount determined on a case-by-case basis.

02 · Scope and Eligible Assets

The following assets are covered by this program: the web application, the main dashboard, the API backend, and the smart contracts deployed on Base Sepolia and Base mainnet.

All user-facing features, authentication flows, API endpoints, smart contract functions, and blockchain interactions are within scope. This includes document hashing, signing, verification, ownership tracking, and subscription management systems.

03 · Eligibility Requirements

To submit a vulnerability report, you must be at least 18 years old and not a resident of a country under international sanctions. You must not be a Cornicular employee, contractor, or immediate family member of someone who is.

Automated scanning tools are permitted only if they do not cause denial of service or degradation of platform performance.

04 · Ticket Quality Expectations

Each vulnerability submission must include a clear description of the issue, steps to reproduce, the potential impact, and any suggested fixes. Submissions without sufficient detail may not be considered.

We value quality over quantity. Well-documented, unique vulnerabilities that demonstrate real-world impact will be prioritized over multiple low-impact findings. Duplicate reports are resolved in favor of the first reporter.

05 · Out of Scope

The following categories of issues are generally not considered for rewards: vulnerabilities in third-party services or libraries, social engineering attacks, denial of service attacks, physical attacks, and issues requiring root access to the server or device.

Known issues that have already been reported, vulnerabilities in deprecated or experimental features, and self-XSS or issues requiring user interaction beyond reasonable scenarios are also excluded.

06 · Reward Policy

We do not currently set fixed reward amounts. Rewards are provided at our discretion for verified, valid reports, with the amount assessed per case based on severity, impact, and the quality of the submission.

Even though the reward amount is not fixed, we are committed to acknowledging well-documented findings. Researchers who submit valid reports may also receive recognition for their contribution.

07 · Submission Process

To submit a vulnerability, send an email to [email protected] with the subject line "Security Report". Include your finding with all required details. You will receive an acknowledgment within 48 hours.

Our security team will review and validate your submission. Please do not disclose the vulnerability publicly until we have confirmed the fix has been deployed.