Vulnerability Disclosure Policy

Report security findings

Infinihash runs production KYC, KYT, and settlement infrastructure for regulated counterparties. If you find a vulnerability, we want to hear about it. This page tells you what is in scope, how we respond, and the safe-harbor commitments you get for testing in good faith.

RFC 9116 security.txt: /.well-known/security.txt · Last reviewed: May 2026.

What you can test

Production Infinihash systems and assets you can reach from the public internet are in scope unless explicitly excluded below. Stay on properties we operate.

In Scope

  • infinihash.com - marketing site and all subpages
  • kyc.infinihash.com - KYC platform UI + API
  • kyt.infinihash.com - KYT platform UI + API
  • clearbox.infinihash.com - settlement portal
  • auth.infinihash.com - cross-subdomain SSO
  • billing.infinihash.com - billing API
  • api.myaitoken.io - MyAi public API
  • myaitoken.io - MyAi marketing + chat UI

Out of Scope

  • Third-party services we use (Stripe, AWS, Cloudflare, Google, Anthropic, Resend, GitHub). Report those to the vendor.
  • Social engineering of staff or customers, including phishing
  • Physical attacks on offices, data centers, or staff
  • DDoS, volumetric, or resource-exhaustion testing
  • Brute force or credential stuffing against accounts (existing or non-existing)
  • Spam, mass form submissions, or content abuse
  • Missing best-practice headers without a concrete impact
  • Self-XSS, clickjacking on pages with no sensitive state, or rate-limit findings without proven impact
  • Outdated software versions absent a working exploit

How to report, what to expect

Send reports to [email protected]. Include a clear writeup, reproduction steps, and any logs or screenshots. PGP is available on request.

To:      [email protected]
Subject: [VDP] Short description of issue

Affected asset:  e.g. kyt.infinihash.com
Severity (your estimate): Low / Medium / High / Critical
Reproduction:    Step-by-step
Impact:          What an attacker can do
Suggested fix:   Optional
Acknowledgement
5 business days
We will reply confirming receipt and triage owner.
Triage
10 business days
Severity assessment + remediation plan shared with you.
Target Fix - High/Critical
30 days
Coordinated disclosure on a longer timeline if needed.
Public Disclosure
90 days
Standard window from initial report unless extended by agreement.

Good-faith research is welcome

If you make a good-faith effort to comply with this policy during your security research, Infinihash will:

We agree to

  • Not pursue or support legal action against you under the CFAA, DMCA anti-circumvention provisions, or similar laws, including state computer-crime statutes
  • Not initiate complaints to your employer or to law enforcement
  • Treat your research as authorized for the in-scope systems listed above
  • Work with you on coordinated disclosure timelines and credit you in the hall of fame below, with permission
  • Reply to every good-faith report - even ones that turn out to be duplicates or out of scope

You agree to

  • Stay within the in-scope assets listed above
  • Avoid privacy violations, data destruction, service degradation, or interruption of business
  • Use only your own test accounts, or accounts you have explicit written authorization to use
  • Stop testing and notify us immediately if you encounter any user data (PII, KYC documents, wallet keys)
  • Give us a reasonable window to remediate before public disclosure
  • Make a good-faith effort not to disrupt service - if you have to choose, lean toward stopping

This policy is adapted from the disclose.io open-source VDP framework.

Bounty status

Infinihash does not currently run a paid bug bounty. We plan to launch a formal program on HackerOne in Q3 2026. In the meantime we credit researchers in the hall of fame, write personal thank-you notes, and ship swag where we have an address on file.

Bug bounty coming Q3 2026 via HackerOne

Hall of fame

Researchers who have responsibly disclosed real issues to Infinihash. Be the first.

No reports credited yet. Submit a finding and we will list you here, with your permission.