tetrac.xyz / security

Responsible
Disclosure

We value the work of security researchers. If you discover a vulnerability in TTC, please report it privately so we can fix it before it affects users.

Initial response
≤ 24 hours
Encryption
PGP supported
Policy expires
2027-03-30

Scope

In scope
  • tetrac.xyz and all subdomains
  • Authentication & session management
  • API endpoints (/api/auth/*, /api/v1/*)
  • x402 payment verification flows
  • Client-side encryption & key storage
  • Cross-site scripting (XSS)
  • SQL / NoSQL injection
  • IDOR & privilege escalation
  • Sensitive data exposure
Out of scope
  • Third-party exchange APIs (Binance, Bybit, etc.)
  • On-chain smart contracts not deployed by TTC
  • Denial-of-service attacks
  • Physical infrastructure
  • Social engineering of TTC staff
  • Findings from automated scanners (unverified)
  • Issues requiring physical device access

How to Report

01
Reproduce
Confirm the vulnerability is real and reproducible. Document every step needed to trigger it.
02
Document
Write a clear report: vulnerability type, affected URL/component, impact rating, and proof-of-concept.
03
Email
Send your report to security@tetrac.xyz. Encrypt with our PGP key for sensitive findings.
04
Coordinate
We will acknowledge within 24 hours and work with you on a coordinated disclosure timeline.
Primary contact
security@tetrac.xyz

Response Timeline

01
Acknowledgment
24h
We confirm receipt of your report
02
Triage
5 days
Severity assessed, team assigned
03
Patch
30 days
Fix developed and deployed (critical: faster)
04
Disclosure
90 days
Public disclosure coordinated with researcher

Rules of Engagement

Test only on accounts you own or with explicit permission
Stop testing immediately upon discovering sensitive user data
Report findings promptly rather than sitting on them
Provide enough detail to reproduce and fix the issue
Access, modify, or exfiltrate user data beyond proof-of-concept
Disrupt production services or degrade platform performance
Publicly disclose before coordinated disclosure window closes
Conduct social engineering or phishing against TTC users or staff

Safe Harbor

TTC considers security research conducted under these guidelines to be authorized conduct. We will not initiate legal action against researchers who discover and report vulnerabilities in good faith and in compliance with this policy. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make known that your actions were conducted in accordance with this policy.

Policy canonical URL: https://tetrac.xyz/.well-known/security.txt·Expires: 2027-03-30

Acknowledgments

// No entries yet — be the first responsible researcher listed here