Security policy

Public summary. Internal hardening checklist is kept in the repo's SECURITY.md.

Reporting a vulnerability

  1. Email security@rugguard.io. Do not open a public issue.
  2. Include: description, steps to reproduce, impact assessment, and any PoC needed (no exploitation beyond what is necessary).
  3. We acknowledge within 72 hours and provide an initial assessment within 7 days.
  4. For CVSS ≥ 7 issues we patch and deploy within 30 days; lower-severity within 90 days.
  5. We credit reporters publicly unless they ask to remain anonymous.
  6. We do not pursue legal action against good-faith research that follows this process.

Out of scope as "security"

What we protect against

What RugGuard does not guarantee

RugGuard returns best-effort analytics. It is not a security audit, not investment advice, and not a guarantee that a flagged-as-safe contract is safe or that a flagged-as-risky contract is malicious. Both false positives and false negatives are expected. Liability is capped at the cost of the call. See /terms.html.