Security is the absolute highest priority for the Aegis RWA Protocol. As a platform handling Real-World Assets and financial value on the Stellar blockchain, we treat all potential vulnerabilities with the utmost seriousness.
Currently, the Aegis RWA Protocol is in the Testnet phase. Security patches are applied exclusively to the main branch of our repositories.
| Repository | Supported |
|---|---|
| aegis-contracts | ✅ Yes |
| aegis-sdk | ✅ Yes |
| aegis-dashboard | ✅ Yes |
DO NOT OPEN A PUBLIC GITHUB ISSUE TO REPORT A SECURITY VULNERABILITY.
Public disclosure of a vulnerability puts user funds and institutional assets at risk. We ask that you practice responsible disclosure by following this process:
- Email security@aegisrwa.dev immediately.
- Include a detailed description of the vulnerability, including steps to reproduce the exploit.
- Include any relevant Proof of Concept (PoC) code or Soroban test environments.
- We will acknowledge receipt of your vulnerability report within 24 hours.
- We will provide an initial assessment and estimated timeline for a fix within 72 hours.
- We will maintain active communication with you throughout the patching and deployment process.
We deeply appreciate the efforts of security researchers and white-hat hackers who help keep the Aegis RWA ecosystem safe.