Vulnerability Disclosure Policy
We take user funds and service integrity seriously. This policy is written for security researchers, white-hat communities, and good-faith users who find and report vulnerabilities in AllSwap — defining the reporting workflow, scope, and legal safe harbor.
In Scope
This policy covers vulnerabilities in the following assets: (a) all web apps and APIs under the allswap.io domain and its subdomains; (b) authentication and session security of the AllSwap Telegram support account @allswapservice; (c) any infrastructure directly operated by AllSwap and exposed as a public service. Underlying decentralized settlement protocols, on-chain market-makers, and third-party wallets are out of scope — please report those to the relevant parties.
Out of Scope
The following are not covered by this policy — please do not report them: (a) denial-of-service (DoS / DDoS) attacks and traffic amplification; (b) social engineering attacks (phishing, support impersonation, etc.); (c) publicly known vulnerabilities in third-party dependencies (please report upstream); (d) attack chains requiring victims to install malware themselves; (e) reports about missing security headers without demonstrable impact; (f) email SPF / DKIM configuration reports (unless a working takeover can be demonstrated).
Reporting Workflow
Please submit reports to [email protected], prefixing the subject with [SECURITY]. Each report should include: (1) a description of the vulnerability and impact assessment; (2) step-by-step reproduction; (3) affected URLs / components / parameters; (4) how you would like to be credited (real name / handle / anonymous). If you need encrypted communication, mention it in the email and we will coordinate a PGP key exchange separately. For urgent matters, reach out via Telegram @allswapservice and support will route the report internally.
Response SLA
We commit to: (a) an initial response within 48 hours of receiving your report; (b) vulnerability confirmation and severity rating within 7 days; (c) for high-severity issues (direct fund risk, user data exposure), targeting a fix within 30 days; (d) for medium and low severity, scheduling remediation accordingly and replying to the researcher within a reasonable window. Once fixed, we will notify the reporter and coordinate a public disclosure timeline.
Safe Harbor
We will not pursue legal action against researchers who comply with this policy and act in good faith — including, but not limited to: using test accounts to probe public interfaces, reporting vulnerabilities, and retaining the minimum proof needed to reproduce. Safe Harbor does not apply to: (a) targets outside the In Scope list; (b) accessing, downloading, or publishing real user data; (c) destructive testing that degrades service availability; (d) using a vulnerability as leverage for extortion or coercive disclosure threats.
Prohibited Conduct
The following actions fall outside Safe Harbor, and we reserve the right to pursue legal remedies: (a) accessing, downloading, or publishing real users' assets, keys, or personal information; (b) destructive testing against production systems that may affect other users (e.g., large-scale data modification or deletion); (c) extorting AllSwap or any third party using a vulnerability; (d) publicly disclosing a vulnerability without coordinated timing; (e) any activity that exceeds legitimate research purposes.
Acknowledgments
We are grateful to every researcher who reports vulnerabilities responsibly and helps strengthen AllSwap. Once a fix has shipped and the reporter consents to public credit, we will list contributors here in chronological order (report date, attribution, brief issue summary). The list is currently empty — we are just getting started and look forward to our first contributor.
Contact and Effective Date
This policy is governed by the laws of the Hong Kong Special Administrative Region. For questions, disputes, or clarifications about this policy, contact us at [email protected]. An RFC 9116 security.txt file is hosted at https://allswap.io/.well-known/security.txt and contains machine-readable metadata for this policy. This policy takes effect on the "Effective" date above and may be updated from time to time — updated versions will be published on this page.

