> ## Documentation Index
> Fetch the complete documentation index at: https://docs.proofable.me/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Disclosure

> Responsible disclosure policy for reporting security vulnerabilities.

Proofable supports responsible, private vulnerability disclosure.

## Reporting Channel

Do not open public issues for undisclosed vulnerabilities.

* Primary contact: `dev@proofable.me`
* Secondary contact: `info@proofable.me`
* Include affected component, impact, reproduction details, and mitigation suggestions.

## Disclosure Expectations

* We acknowledge valid reports and triage based on severity.
* We aim to respond to valid reports within 48 hours.
* Please provide reasonable remediation time before public disclosure.
* Avoid actions that could harm users, infrastructure, or third parties.

## Scope Examples

* API authentication and authorization flaws
* Signature verification bypasses
* Proof visibility/privacy escalation issues
* Replay/rate-limit bypasses
* Smart-contract and verifier integrity issues

## Out-of-Scope Examples

* Social engineering
* Denial-of-service traffic without exploit details
* Issues requiring physical access to user devices
* Vulnerabilities in third-party services outside Proofable control

## Safe Harbor

Proofable does not pursue legal action against good-faith researchers who follow this policy, avoid privacy violations, and promptly report findings.
