security: harden vulnerability disclosure policy (#3419)
What changed, and why it matters
This commit only updates the project's written security policy (docs/SECURITY.md). It does not change any application code, fix a bug, or patch a vulnerability. It clarifies how researchers should report security issues, adds safe-harbor language, defines scope, and introduces a discretionary reward policy. There is no direct security risk or security improvement to the software itself.
No action required beyond normal review of policy text. If auditing the project, treat this commit as a process/policy update, not a code security fix or regression.
Security signals we found
Documentation-only change to security policy
Adds safe-harbor and coordinated disclosure language
Adds PGP key and encrypted email reporting channel
Defines in-scope and out-of-scope findings
Introduces discretionary reward policy
Evidence from the diff
The diff is limited to docs/SECURITY.md. It replaces a short reporting section with a comprehensive vulnerability disclosure policy: private GitHub advisories and encrypted email as reporting channels, PGP key/fingerprint, safe-harbor commitment, response SLAs, scope and out-of-scope definitions, and a discretionary bug-bounty policy. No source code, build scripts, dependencies, or configuration files are modified.
Changed components
docs/SECURITY.mdInspect captured patch +95 / −6
diff --git a/docs/SECURITY.md b/docs/SECURITY.md
index e7c6baa..0198e72 100644
--- a/docs/SECURITY.md
+++ b/docs/SECURITY.md
@@ -1,12 +1,101 @@
# Security Policy
-## Reporting a Vulnerability
+Cake Wallet is developed by **Cake Labs LLC**. We take the security and privacy of
+our users seriously and welcome reports from security researchers.
-If you need to report a vulnerability, please either:
+> **Cake Wallet is not affiliated with CAKE.com, Clockify, or security.cake.com.**
+> Those services belong to unrelated companies. The only official vulnerability
+> disclosure channels for Cake Wallet are the ones listed on this page and at
+> https://cakewallet.com/security.
-* Open a security advisory: https://github.com/cake-tech/cake_wallet/security/advisories/new
-* Send an email to `dev@cakewallet.com` with details on the vulnerability
+## Reporting a vulnerability
-## Supported Versions
+**Please do not open a public issue, pull request, or social-media post for a
+security vulnerability.** Public disclosure before a fix is available puts users'
+funds and privacy at risk. Use one of the private channels below and we will
+coordinate a fix and disclosure with you.
-As we don't maintain previous versions of the app, only the latest release for each platform is supported and any updates will bump the version number.
+1. **GitHub private security advisory (preferred).**
+ [Report a vulnerability](https://github.com/cake-tech/cake_wallet/security/advisories/new).
+ This gives you a private, structured thread with the maintainers and is the
+ fastest way to reach us.
+2. **Encrypted email.** Send details to **security@cakewallet.com**. For sensitive
+ reports, please encrypt with our PGP key:
+ - Key: https://cakewallet.com/.well-known/cakewallet-security.asc
+ - Fingerprint: `DC91 6520 0271 AC6A 0533 3D3C BFE7 D9A5 0E4D 3A0A`
+
+Both channels are monitored and automatically raise an alert in our internal
+security channel, so reports will not be missed.
+
+### What to include
+
+- A clear description of the issue and its security impact.
+- Step-by-step reproduction, ideally with a proof of concept.
+- Affected platforms (iOS, Android, macOS, Linux, Windows) and app version.
+- Affected wallet types / chains, if applicable.
+- Any relevant logs, addresses, or transaction IDs (for on-chain issues).
+
+If you used AI tooling to find or write up the report, please say so.
+
+## Our commitment (safe harbor)
+
+We consider security research conducted in good faith under this policy to be
+authorized. We will not pursue or support legal action against researchers who:
+
+- make a good-faith effort to avoid privacy violations, data destruction, and
+ interruption or degradation of our services;
+- only interact with accounts they own or have explicit permission to access; and
+- give us a reasonable opportunity to fix an issue before disclosing it publicly.
+
+If in doubt about whether an action is authorized, ask us first at
+security@cakewallet.com.
+
+## What to expect
+
+- **Acknowledgement:** within **2 business days**.
+- **Triage and initial assessment:** within **7 business days**.
+- **Coordinated disclosure:** we aim to ship a fix and coordinate public
+ disclosure within **90 days** of the report. We will keep you updated on
+ progress and agree on a disclosure date with you.
+- **Credit:** with your permission, we are happy to publicly credit you for the
+ report once a fix is released.
+
+## Scope
+
+**In scope:** the Cake Wallet and Monero.com applications and the code in this
+repository and its sibling `cake-tech` repositories — anything that could lead to
+loss of funds, exposure of keys or seeds, a privacy leak, or a
+failed/incorrect transaction.
+
+**Out of scope:** issues in third-party services, exchange/swap providers, or
+nodes we do not operate; reports generated solely by automated scanners without a
+demonstrated impact; low-severity or informational issues on our marketing and
+landing websites (for example reflected or self-XSS, missing security headers,
+clickjacking on pages with no sensitive actions, or SPF/DMARC and cookie-flag
+nitpicks) that do not affect the app or user funds; and social-engineering or
+physical attacks.
+
+## Rewards
+
+At our **sole discretion**, we may offer a reward for a valid report. To be
+eligible, a report must:
+
+- be submitted **privately** through one of the channels above (a GitHub private
+ security advisory or `security@cakewallet.com`) — anything disclosed publicly or
+ sent through other channels is not eligible; and
+- identify a genuine vulnerability with real impact on users — typically loss of
+ funds, exposure of keys or seeds, a privacy leak, or a failed or incorrect
+ transaction.
+
+Trivial or low-impact findings are **not** eligible — for example, reflected XSS
+or other low-severity issues on our marketing websites, missing security headers,
+hardening or best-practice suggestions, automated-scanner output without a working
+proof of concept, or already-known issues. There is no fixed bounty and no
+guaranteed payout; whether a report qualifies, and any amount, are determined
+solely by Cake Labs LLC.
+
+## Supported versions
+
+We do not maintain previous releases. Only the **latest release for each platform**
+is supported; security fixes are delivered in new versions. Please keep Cake Wallet
+up to date.
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.