Skip to main content
Toknbase
SECURITY · RESPONSIBLE DISCLOSURE

Responsible Disclosure

We take security seriously. If you discover a vulnerability in Toknbase, we want to know about it — and we commit to working with you to resolve it quickly.

How to Report

Send your vulnerability report by email. We do not use a bug bounty platform — direct email gets to us fastest.

support.toknbase@gmail.com

Include: steps to reproduce, potential impact, and any proof-of-concept

Send report →

Tip

Please do not open a public GitHub issue or disclose the vulnerability publicly before we have had a chance to investigate. Premature disclosure can put other users at risk.

What to Expect

  1. Within 72 hours

    Acknowledgment of your report with a tracking reference.

  2. Within 7 days

    Initial assessment and severity classification (Critical / High / Medium / Low).

  3. Within 90 days

    Target resolution. Critical and High severity issues are prioritized and fast-tracked.

  4. After resolution

    Coordinated public disclosure. With your permission, we will credit you in the advisory.

In Scope

  • The Toknbase web application (toknbase.net)
  • The Internet Computer canister (xi7mc-uaaaa-aaaan-q5raa-cai)
  • The @toknbase/mcp-server npm package
  • The @toknbase/cli npm package
  • Client-side encryption implementation (AES-256-GCM)

Note

Toknbase runs on the Internet Computer (ICP) — a decentralized blockchain network. There are no traditional servers, databases, or cloud infrastructure to exploit. On-chain security differs from conventional web app security.

Out of Scope

  • Denial of service (DoS / DDoS) attacks
  • Social engineering of team members
  • Physical attacks against infrastructure
  • Vulnerabilities in third-party services (Stripe, Internet Identity, ICP boundary nodes)
  • Issues already reported or publicly known

Safe Harbor

We will not pursue legal action against security researchers who discover and report vulnerabilities in good faith, following this disclosure policy. We ask that you do the same — give us reasonable time to investigate and fix the issue before disclosing publicly.

Questions about this policy? Emailsupport.toknbase@gmail.com

Was this page helpful?