Documentation
Docs45. Responsible Disclosure

45. Responsible Disclosure

The Kortana Foundation maintains a proactive, transparent vulnerability disclosure program. Security researchers, node operators, and ecosystem developers who discover potential vulnerabilities in kortana-node, quorlinc, or standard protocol smart contracts are requested to report findings directly to the core security team:

  • Security Email: support@kortana.network
  • PGP Encryption: All vulnerability submissions should be encrypted using the official Kortana Security PGP Public Key published on the foundation website.
  • Submission Requirements: Please include a detailed technical description of the vulnerability, step-by-step reproduction instructions, proof-of-concept exploit code (if applicable), and an assessment of potential impact.
  • Bug Bounty Program: Valid, responsibly disclosed security vulnerabilities are eligible for financial bounty rewards based on severity ratings (Critical, High, Medium, Low) evaluated under the CVSS v3.1 framework.
  • Public Disclosure Policy: We request that researchers allow a 90-day coordinated disclosure window to enable the core engineering team to develop, test, and deploy software patches before disclosing details publicly.

Part XII — Token & Resource Standards