chainstrip Book a demo

security

Vulnerability Disclosure Policy

ChainStrip · Last updated: 2026-08-30

ChainStrip builds security tooling, so we hold ourselves to the standard we sell. If you believe you've found a security issue in our product or our web properties, we want to hear from you, and this page explains how that works and what you can expect from us.

Scope

In scope:

Out of scope:

How to report

Email security@chainstrip.com with:

If you prefer encrypted mail, use our PGP key (also listed in security.txt). Fingerprint: 1272 C605 54DD 3143 C11D D0F3 5579 3FD3 FF69 E118.

What we commit to

We do not currently run a paid bug bounty. This is a disclosure program: what we offer is a fast, honest, technically competent response.

Coordinated disclosure

We ask that you give us a reasonable window to remediate before public disclosure — 90 days is the default we work to, and we'll tell you early if a fix needs longer and why. We're glad to coordinate publication timing, and for confirmed issues we'll share our advisory draft with you before it goes out.

Safe harbor

We consider security research conducted in good faith and within this policy to be authorized. We will not initiate legal action against you for good-faith research that: respects the scope above, avoids privacy violations and data destruction, does not degrade service for others, and gives us a reasonable opportunity to remediate before disclosure. If you're ever unsure whether something is covered, ask first at security@chainstrip.com — we'd rather answer a question than handle an incident.

This authorization applies only to systems we own. It cannot extend to our customers' environments or to third-party services.


Questions about this policy: security@chainstrip.com