F-12 Security Public

Vulnerability Disclosure Policy

AssetShop LLC · Pennsylvania, USA · Effective 2026 · Counsel-ready draft

Effective date: 2026-06-06 (GA launch)

Anchored: 2026-05-19 · v1.0

Contact: AssetShopCo@gmail.com (primary) · AssetShopCo@gmail.com (until DNS verified)


Our commitment

AssetShop welcomes good-faith security research. We commit to:

This is a commitment, not aspirational language. Test it.


Reporting

Preferred channel: email AssetShopCo@gmail.com (until DNS live: AssetShopCo@gmail.com)

PGP key: published at /.well-known/security-pgp.asc on trust.enterprise.assetshop.eth

Include:

Do not:


Scope · in-scope

AssetNotes
*.assetshop.eth (5 IPFS sites)enterprise / sco / platform / demo / trust
*.assetshop.com (when DNS live)All marketing + product surfaces
api.assetshop.com (when deployed)Backend API endpoints
@assetshop/verify-cli (npm)Verification CLI tool
AssetShop SCO product (post-GA)Customer-facing product surfaces
AssetShopAnchor.sol on Base L2Anchor contract (specific deployment address)

Scope · out-of-scope

AssetWhy
Customer ERP systemsBelong to the customer; we don't authorize testing
AWS / GCP / AzureReport to the cloud provider directly
Base L2 chain itselfCoinbase / Optimism Foundation handles
Open-source libraries we depend onReport upstream first; we'll patch when they do
AssetShop staff personal accountsPersonal scope only
Marketing-only surfaces with no authCosmetic issues without security impact

What we'll pay

Currently: Public acknowledgment + swag + a thank-you call from the founder.

Post-funding (target Q1 2027): Cash bounties via HackerOne or Bugcrowd, scaled by severity.

Indicative future ranges (when bounty program launches):

SeverityCVSSBounty
Critical9.0-10.0$5,000-$15,000
High7.0-8.9$1,500-$5,000
Medium4.0-6.9$500-$1,500
Low0.1-3.9$100-$500
Informational-$50 + swag

Today we don't pay cash - but we will name you in the hall of fame, give you a written letter for your CV, and the founder will personally thank you and discuss your finding.


Hall of Fame

The first 10 researchers to report a valid vulnerability (any severity) receive permanent listing at /hall-of-fame on trust.enterprise.assetshop.eth, plus a signed certificate. The Hall of Fame is launched at GA.


Triage process

  1. You report → we acknowledge within 48 hours
  2. We assign severity (CVSS) and internal ticket
  3. We confirm/dispute reproducibility within 5 business days
  4. We provide patch timeline based on severity:
  1. We patch
  2. We notify you of patch + ask about coordinated disclosure timing
  3. We publish a public advisory (with your acknowledgment, if you consent)
  4. We add you to Hall of Fame

Coordinated disclosure

We respect the reporter's timeline. Default disclosure is:

If we cannot agree, we will not retaliate. We'll let you publish on your timeline; we'll publish our advisory on ours. Coordinated disclosure is the goal but not the only path.


What we'll never do


What we expect from researchers

If you act in good faith per this policy, we will not pursue legal action regardless of outcome.


Edge cases

"I found something but it's only theoretical." Report it anyway. We'll triage and respond.

"I found something but it requires admin access I already have." That's not a vulnerability; that's authorized use. But if your access path includes an unintended escalation, do report.

"I found a vulnerability in an AssetShop customer's ERP through AssetShop." Stop, do not access customer data, and report immediately. We'll coordinate with the customer.

"I'm a competitor." Doesn't matter. Good-faith reports are welcome from anyone.

"I want to remain anonymous." Fine. Use a pseudonym + ProtonMail; we'll still respond.


Calibration discipline

Every confirmed vulnerability becomes a calibration ledger row: CLM_YYYY_QN_VULN_NNN. Severity, patch timeline, and remediation status are public (vulnerability details remain confidential until coordinated disclosure date).

This means AssetShop publicly tracks its own vulnerabilities. The calibration discipline does not exempt our own product from honest disclosure.


Updates

This policy is reviewed annually. Material changes are versioned (this is v1.0).


Bottom line: if you find something, tell us. We will treat you well. We will fix what you found. We will give you credit. We will not sue you.

Theme