Skip to content

Security: sandhywarhol/chainvolio

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x (current) Yes

Reporting a Vulnerability

ChainVolio handles wallet signatures and professional identity data. Security issues are taken seriously.

Do NOT open a public GitHub issue for security vulnerabilities.

To report a vulnerability:

  1. Email: gressandhyrangga@gmail.com (or contact via X: @sandhywarhol)
  2. Include: description, steps to reproduce, potential impact
  3. We will respond within 48 hours and coordinate a fix before public disclosure

Scope

In scope:

  • Authentication and wallet signature verification
  • Row-Level Security (RLS) bypass
  • Attestation record tampering
  • CV snapshot integrity violations
  • Cross-recruiter data leakage

Out of scope:

  • Social engineering attacks
  • Issues in third-party dependencies (Phantom, Solflare, Supabase)

There aren't any published security advisories