# Sealed (seal.epochpay.today) — Vulnerability disclosure # RFC 9116 Contact: mailto:security@seal.epochpay.today Contact: https://seal.epochpay.today/security/report Expires: 2027-05-12T00:00:00.000Z Encryption: https://seal.epochpay.today/security/pgp.txt Acknowledgments: https://seal.epochpay.today/security#hall-of-fame Preferred-Languages: en Canonical: https://seal.epochpay.today/.well-known/security.txt Policy: https://seal.epochpay.today/security#vuln # In scope # seal.epochpay.today # chain.epochcoreqcs.com # /api/seal # /api/pilot # /api/security-report # /v/ verifier # # Out of scope # social engineering # denial-of-service # third-party services we don't operate (Cloudflare, Resend, Base L2) # # Severity guidance # Critical : remote code execution, secret key disclosure, chain-anchor forgery # High : SQL/NoSQL injection, auth bypass, sub-processor data leak # Medium : stored XSS, IDOR on intake forms, replay of pilot intakes # Low : reflected XSS without session, missing security headers, info disclosure # # Safe harbor # Good-faith research that complies with this policy and avoids accessing # customer data beyond what's strictly necessary will not result in legal action.