Security
Found a vulnerability? We want to hear about it, safely, for both of us.
Reporting a vulnerability
Use the vulnerability report form — it takes attachments (screenshots, proof-of-concept files) and lands directly in our review queue.
Or email security@siliconrelay.com with a description of the issue, steps to reproduce, and the affected URL or endpoint. Plain email is fine; we read every report.
Prefer encrypted mail? Encrypt to our PGP key — verify its fingerprint against this page:
1921 799A DFE9 BA53 EAC2 E89F 5EA4 55B3 E205 49D5
A machine-readable version of this policy lives at /.well-known/security.txt (RFC 9116).
Scope
In scope
- The SiliconRelay dashboard and public pages (login, signup, help, this site).
- The ad-serve surface:
/ad,/click, the beacons, and the ad tag snippet. - Deposit and payout flows (wallet pages, payment webhooks).
Out of scope
- Third-party services we depend on (payment processors, RPC providers, hosting).
- Publisher sites that merely run our ad tag.
- Denial-of-service or volumetric findings, and automated-scanner reports without a demonstrated impact.
- Social engineering, phishing, or physical attacks against our team.
- Email-hygiene reports (SPF/DKIM/DMARC) without an exploit path.
Rules of engagement
- Only test against accounts you own. Never access, modify, or delete another user's data.
- Don't degrade the service: no DoS, no high-volume automated scanning.
- If you hit personal data or money movement, stop and report. Don't go further to "prove" impact.
- Give us a reasonable window (90 days) to fix before any public disclosure.
Safe harbor
We will not pursue or support legal action against researchers who make a good-faith effort to follow these rules. We consider such research authorized under applicable anti-hacking and anti-circumvention laws. If a third party takes action against you for research that complied with this policy, we will make it known that you acted in good faith.
Rewards
We don't run a formal bug bounty. Rewards are at our discretion — no guaranteed payouts — but meaningful reports earn our thanks and, with your permission, a place in the Hall of Fame below.
Response targets
| Acknowledgement | 48 hours |
| Initial triage | 7 days |
| Resolution updates | As available |
Hall of Fame
No entries yet, be the first.