| Version | Supported |
|---|---|
| 0.1.x (current) | Yes |
ChainVolio handles wallet signatures and professional identity data. Security issues are taken seriously.
Do NOT open a public GitHub issue for security vulnerabilities.
To report a vulnerability:
- Email: gressandhyrangga@gmail.com (or contact via X: @sandhywarhol)
- Include: description, steps to reproduce, potential impact
- We will respond within 48 hours and coordinate a fix before public disclosure
In scope:
- Authentication and wallet signature verification
- Row-Level Security (RLS) bypass
- Attestation record tampering
- CV snapshot integrity violations
- Cross-recruiter data leakage
Out of scope:
- Social engineering attacks
- Issues in third-party dependencies (Phantom, Solflare, Supabase)