Vulnerability Disclosure Program

Find something? Tell us.

Infinihash runs production KYC, KYT, and settlement infrastructure for regulated counterparties. This is a $0 disclosure program — there is no cash bounty today. Good-faith researchers get safe harbor, a fast acknowledgement, and public credit instead.

/.well-known/security.txt · Last reviewed: September 2026 · See the full policy detail at /security.

What you can test

Production Infinihash systems reachable from the public internet are in scope unless excluded below.

In Scope

  • infinihash.com — marketing site and all subpages
  • kyc.infinihash.com — KYC platform UI + API
  • kyt.infinihash.com — KYT platform UI + API
  • auth.infinihash.com — cross-subdomain SSO
  • billing.infinihash.com — billing API

Out of Scope

  • Denial of service, volumetric, or resource-exhaustion testing
  • Social engineering of staff or customers, including phishing
  • Physical attacks on offices, data centers, or staff
  • Third-party services we use (Stripe, AWS, Cloudflare, Google, Anthropic, Resend). Report those to the vendor directly.

This is a summary. The complete, authoritative in-scope asset list (including additional platform surfaces) lives on /security — check there before testing anything not listed above.

Send us what you found

Email [email protected] with a clear writeup, reproduction steps, and any logs or screenshots. PGP is available on request.

To:      [email protected]
Subject: [VDP] Short description of issue

Affected asset:  e.g. kyt.infinihash.com
Severity (your estimate): Low / Medium / High / Critical
Reproduction:    Step-by-step
Impact:          What an attacker can do
Suggested fix:   Optional
Acknowledgement
5 business days
We confirm receipt and assign a triage owner.
Coordinated Disclosure
90 days
Our ask before public disclosure, extendable by mutual agreement.

Good-faith research is welcome

If you make a good-faith effort to comply with this policy, Infinihash will:

We agree to

  • Not pursue or support legal action against you under the CFAA, DMCA anti-circumvention provisions, or similar state computer-crime statutes
  • Not initiate complaints to your employer or to law enforcement
  • Treat your research as authorized for the in-scope systems above
  • Work with you on a coordinated disclosure timeline and credit you below, with your permission

You agree to

  • Stay within the in-scope assets listed above (or on /security)
  • Avoid privacy violations, data destruction, or service disruption
  • Use only your own test accounts, or ones you're explicitly authorized to use
  • Stop and notify us immediately if you encounter real user data (PII, KYC documents, wallet keys)
  • Give us a reasonable window to remediate before disclosing publicly

This safe harbor is based on the disclose.io core terms.

No cash bounty today

Infinihash does not run a paid bug bounty right now — this is a $0 recognition-based program. We credit researchers in the hall of fame below, write a personal thank-you, and ship swag where we have an address on file. We are not promising a bounty amount because none exists yet.

Paid bounty via HackerOne planned for Q3 2026

Hall of fame

Researchers who have responsibly disclosed a real issue to Infinihash.

No submissions yet — be the first.