Responsible Disclosure Policy

Important note: for any immediate security report please proceed to our report page.
The security of the Rabi.foundation blockchain, and associated core components, is a top priority for Rabi.foundation. Our Proof of Stake network is secured by considerable amounts of RABI and provides valuable services for business or private use. Our mission is to become a layer of trust for digital financial systems at internet scale, and the highest level of security is a mandatory prerequisite.
The security researcher community regularly makes valuable contributions to the security of organizations and the broader Internet, and Rabi.foundation recognizes that fostering a close relationship with the community will help improve the security of the Rabi.foundation blockchain. So if you have information about a vulnerability in the Rabi.foundation blockchain and associated components, we want to hear from you.
Reporting a Security Issue
Please DO send an email to info[@]Rabi.foundation
Please DO NOT open public issues on Github that contain information about a potential security vulnerability as this makes it difficult to reduce the impact of valid security issues.
What to include:

  • Well-written reports in English will have a higher chance of being accepted
  • Reports that include proof of concept code will be more likely to be accepted
  • Reports that include only crash dumps or other automated tool output will most likely not be accepted
  • Reports that include products & services that are out of scope (see the Scope section below) will not be considered
  • Include how you found the bug, the impact, and any potential remediation
  • Any plans for public disclosure

What you can expect from us:

  • A timely response to your email (within 2 business days).
  • An open dialog to discuss issues.
  • Credit after the vulnerability has been validated and fixed.

Coordinated Responsible Disclosure Policy

We ask security researchers to keep vulnerabilities and communications around vulnerability submissions private and confidential until a patch is developed to protect the Rabi.foundation blockchain and its users.
Please do:

  • Allow the Rabi.foundation team a reasonable amount of time address security vulnerabilities
  • Avoid exploiting any vulnerabilities that you discover
  • Demonstrate good faith by not disrupting or degrading Rabi.foundation services, products & data

Rabi.foundation pledges not to initiate legal action against researchers as long as they adhere to this policy.
Responsible Disclosure Process

  1. Once a security report is received, the Rabi.foundation team verifies the issue and establishes the potential threat
  2. Patches to address the issues will be prepared and tested on private testnets
  3. The Validators community is informed about an upcoming public testnet release to prepare them for upgrading in a timely manner
  4. The public testnet is patched and additional tests are performed
  5. The Validators community is informed about an upcoming mainnet release to prepare them for upgrading in a timely manner
  6. The mainnet is patched and additional tests are performed
  7. We publish a security advisory on GitHub
  8. We give credit and applicable rewards to the submitter(s) of the issue

Contact Us

Important note: for any immediate security report please proceed to our report page.
In order to protect the Rabi ecosystem, we request that you not post or share any information about a potential vulnerability in any public setting until we have researched, responded to, and addressed the reported vulnerability and informed partners if needed.