Documentation
Docs45. Responsible Disclosure
45. Responsible Disclosure
The Kortana Foundation maintains a proactive, transparent vulnerability disclosure program. Security researchers, node operators, and ecosystem developers who discover potential vulnerabilities in kortana-node, quorlinc, or standard protocol smart contracts are requested to report findings directly to the core security team:
- Security Email:
support@kortana.network - PGP Encryption: All vulnerability submissions should be encrypted using the official Kortana Security PGP Public Key published on the foundation website.
- Submission Requirements: Please include a detailed technical description of the vulnerability, step-by-step reproduction instructions, proof-of-concept exploit code (if applicable), and an assessment of potential impact.
- Bug Bounty Program: Valid, responsibly disclosed security vulnerabilities are eligible for financial bounty rewards based on severity ratings (Critical, High, Medium, Low) evaluated under the CVSS v3.1 framework.
- Public Disclosure Policy: We request that researchers allow a 90-day coordinated disclosure window to enable the core engineering team to develop, test, and deploy software patches before disclosing details publicly.