Skip to main content

Security

Report security issues responsibly.

Effective: July 28, 2026 · Version: 2026-07-28

SolTrench API is non-custodial infrastructure. Customers should never send private keys, seed phrases, private RPC credentials, or wallet keypair files to SolTrench. Report suspected vulnerabilities to security@soltrench.io.

In Scope

  • Authentication, API-key, wallet-linking, quota, or websocket token bypasses.
  • Unauthorized access to account, usage-entitlement, audit, or administrative data.
  • Server-side secret exposure, request smuggling, or domain/edge misconfiguration.
  • Incorrect transaction-building behavior that could misrepresent signer or custody boundaries.

Out Of Scope

Market losses, failed trades, token behavior, third-party RPC/provider outages, and social engineering against customers are outside the security-reporting scope, though abuse can still be reported.

How To Report

Include the affected URL or endpoint, a concise description, reproducible steps, expected impact, and any non-sensitive evidence needed to investigate. Do not send private keys, seed phrases, API-key secrets, personal data belonging to another person, or a working exploit that unnecessarily exposes data.

Safe Testing Boundaries

Use only accounts, wallets, and data you control. Stop once you have minimally confirmed an issue. Do not access another person's data, alter or delete data, trade or move funds, degrade availability, use automated high-volume scanning, social-engineer anyone, or test a third-party provider. Obtain written permission before any intrusive testing. SolTrench does not currently operate a bug-bounty or general safe-harbour programme.

Response And Disclosure

Reports are reviewed as beta capacity allows and no response or remediation time is promised. Please allow reasonable time to investigate before public disclosure. SolTrench will not request a wallet secret or ask you to move funds as part of a vulnerability report.

Security.txt

Machine-readable reporting details are available at /.well-known/security.txt.

Terms Acceptable Use Privacy Contact