Skip to content
Documentation/canton-foundation/Canton FoundationView on canton-foundation
canton-foundation/Canton Foundation

Responsible Disclosure - Canton Foundation

Canton Foundation

ResponsibleDisclosure

Last Updated: August 8, 2026

Canton Foundation takes security very seriously for the Canton Network ecosystem, our partners, and our staff. If you are a Security Researcher and have discovered a vulnerability in our website or products, we appreciate your help in disclosing this to us in a responsible manner.

Canton Foundation will engage with security researchers when vulnerabilities are reported to us in accordance with this Responsible Disclosure Policy. We will validate, respond, and fix vulnerabilities in accordance with our commitment to security and privacy. We won’t take legal action against those who discover and report security vulnerabilities in accordance with this Responsible Disclosure Policy. Canton Foundation reserves all of its legal rights in the event of any noncompliance.

Guidelines

Responsible Disclosure helps increase security for affected organizations and the community as a whole. Please follow the guidelines below:

  • Don’t disclose a bug or vulnerability on public notice boards, mailing lists, or other public forums, prior to Responsible Disclosure and an appropriate opportunity for it to be fixed.
  • Do not utilize an exploit to view data without authorization, or compromise the confidentiality or availability.
  • Do not perform an attack that would impact the reliability/availability of services. DDoS/Spam attacks are not allowed.
  • Don’t use scanners or automated tools to find vulnerabilities. They can have unintended consequences or impact.
  • Never attempt non-technical attacks, such as social engineering, phishing, or physical attacks against our employees or infrastructure.
  • Do not ask for compensation from an affected firm or through any “marketplace” for vulnerabilities.

AI Assisted Research Disclosure

When submitting a vulnerability report, you must now declare whether any AI tools (LLMs, AI assistants, copilots, or automated agents) were used to discover, reproduce, or develop the exploit. If AI was used, you must include the exact prompt(s) — and any relevant chat transcript or session export — and skills and MCPs that led to the finding. Reports that do not include this declaration will not be triaged until the required information is provided. This helps the Canton Foundation understand AI-assisted research, perform verification of the submissions and uphold its AI governance commitments.

Researchers who submit significant numbers of unverified, false positive or hallucinated findings may be blocked for a period of time. Disclosure verification can be time consuming so abuse of this resource will not be tolerated.

While researching, we would like you to refrain from:

  • Denial of Service (DOS) and Distributed Denial of Service (DDOS)
  • Spamming
  • Clickjacking
  • Email bombing/Flooding/rate limiting
  • Social Engineering or phishing of Canton Foundation’s staff
  • Any attack against Canton Foundation’s physical property or data centers
  • Scanning Canton Foundation infrastructure or products using automated vulnerability scanners without human verification and contextualisation

Out of Scope

The following should not be reported:

  • Vulnerabilities in Third party SaaS applications and integrations we use
  • Username/E-mail enumeration
  • Missing HTTP security headers or issues related to HTTP headers
  • Missing DMARC, SPF, DANE and CAA records
  • OAuth Misconfiguration
  • Logout Cross-Site Request Forgery
  • EXIF and Geolocation related vulnerabilities
  • Reports of insecure SSL/TLS ciphers (unless accompanied with working proof of concept)

How to Report an Issue

If you believe you have discovered a vulnerability in our software, please contact security@canton.foundation. Please do not publicly disclose suspected vulnerabilities without prior consent from Canton Foundation.

In reporting vulnerabilities, please send details of:

  • Suspected vulnerability.
  • Steps to enable us to reproduce the issue.
  • Your email address and a secure mechanism to contact you.
  • Your name (and/or colleagues) if you would like to be recognized on this page, e.g., your Twitter handle or website as it should be displayed.

You can use the PGP public key below to encrypt your email communication to us. Please include a secure contact mechanism for us to contact you.

Response and Recognition

We will investigate any details you provide and respond as soon as possible, usually one business day.

To acknowledge the first person who alerts us to previously unknown vulnerabilities, we will show our gratitude by placing their name in the Acknowledgements list below. We do not offer a bug bounty program and compensation requests will not be considered in compliance with this Responsible Disclosure Policy.

Acknowledgements

Canton Foundation thanks the following individuals and organizations that have identified vulnerabilities in accordance with this Responsible Disclosure Policy:

Changes

We may revise these guidelines from time to time without notice.