Responsible Disclosure
We take security seriously. If you discover a vulnerability in Toknbase, we want to know about it — and we commit to working with you to resolve it quickly.
How to Report
Send your vulnerability report by email. We do not use a bug bounty platform — direct email gets to us fastest.
support.toknbase@gmail.com
Include: steps to reproduce, potential impact, and any proof-of-concept
Tip
What to Expect
Within 72 hours
Acknowledgment of your report with a tracking reference.
Within 7 days
Initial assessment and severity classification (Critical / High / Medium / Low).
Within 90 days
Target resolution. Critical and High severity issues are prioritized and fast-tracked.
After resolution
Coordinated public disclosure. With your permission, we will credit you in the advisory.
In Scope
- The Toknbase web application (toknbase.net)
- The Internet Computer canister (xi7mc-uaaaa-aaaan-q5raa-cai)
- The @toknbase/mcp-server npm package
- The @toknbase/cli npm package
- Client-side encryption implementation (AES-256-GCM)
Note
Out of Scope
- Denial of service (DoS / DDoS) attacks
- Social engineering of team members
- Physical attacks against infrastructure
- Vulnerabilities in third-party services (Stripe, Internet Identity, ICP boundary nodes)
- Issues already reported or publicly known
Safe Harbor
We will not pursue legal action against security researchers who discover and report vulnerabilities in good faith, following this disclosure policy. We ask that you do the same — give us reasonable time to investigate and fix the issue before disclosing publicly.
Questions about this policy? Emailsupport.toknbase@gmail.com