§ Policy

Coordinated disclosure

We find things that move real money. How they get told, to whom, and when is not an afterthought — it is part of the engagement. This is the policy every mandate runs under.

Version 2.1 · Effective 2026.08.01

01Principle

A vulnerability is a live liability until it is fixed. Our default is coordinated disclosure: the affected team gets the finding, the proof, and the time to remediate before anyone else — including the public — learns it exists.

02What you receive

03Embargo window

From the moment a finding is delivered, a standard embargo of 90 days applies before any public write-up. The clock pauses while a fix is actively being deployed and resumes once it stalls. Critical findings with funds at immediate risk are handled privately and continuously until mitigated — there is no fixed timer on an active exploit.

04Third-party dependencies

If a finding implicates a protocol you depend on but do not control, we notify that party through their published security contact, in coordination with you. We do not disclose your identity or scope to a third party without your consent unless withholding it would leave user funds in active danger.

05Publication

After the embargo, and only with the affected team's sign-off, a finding may be published as a redacted case study — mechanism and lesson, never live keys, addresses, or anything that re-enables the exploit. Clients may opt out of publication entirely; many do.

06Reporting to us

If you have found an issue in our own site or infrastructure, see our security.txt and write to security@mephistopheles.zip using our PGP key. We acknowledge within two business days.


Questions about this policy → audits@mephistopheles.zip

See also → Terms of engagement · Privacy policy · security.txt