01Principle
A vulnerability is a live liability until it is fixed. Our default is coordinated disclosure: the affected team gets the finding, the proof, and the time to remediate before anyone else — including the public — learns it exists.
02What you receive
- A written finding with severity, affected contracts, and on-chain preconditions.
- A reproduction: the exact steps and a runnable script that moves value in a mainnet fork.
- A remediation path, and a re-test of the fix at no additional charge within the engagement window.
03Embargo window
From the moment a finding is delivered, a standard embargo of 90 days applies before any public write-up. The clock pauses while a fix is actively being deployed and resumes once it stalls. Critical findings with funds at immediate risk are handled privately and continuously until mitigated — there is no fixed timer on an active exploit.
04Third-party dependencies
If a finding implicates a protocol you depend on but do not control, we notify that party through their published security contact, in coordination with you. We do not disclose your identity or scope to a third party without your consent unless withholding it would leave user funds in active danger.
05Publication
After the embargo, and only with the affected team's sign-off, a finding may be published as a redacted case study — mechanism and lesson, never live keys, addresses, or anything that re-enables the exploit. Clients may opt out of publication entirely; many do.
06Reporting to us
If you have found an issue in our own site or infrastructure, see our security.txt and write to security@mephistopheles.zip using our PGP key. We acknowledge within two business days.