generated: '2026-07-17' method: searched source: https://docs.alpenlabs.io/community/security probe: false summary: >- Alpen Labs runs a responsible-disclosure program with a dedicated security contact and an active bug bounty on Immunefi for critical vulnerabilities, and publishes third-party audit reports. Captured by searching the docs security page; the mechanical probe did not fire because the published /.well-known/security.txt lists only a GitHub-issues Contact and has an expired Expires date. policy: - https://docs.alpenlabs.io/community/security - https://immunefi.com/ bug_bounty: program: Immunefi scope: critical vulnerabilities contact: - security@alpenlabs.io - https://github.com/alpenlabs/alpen/issues security_txt: https://www.alpenlabs.io/.well-known/security.txt audits: - firm: Least Authority date: '2025-08' scope: Orchestration Layer - firm: Halborn date: '2025-11' scope: Secret Service (strata-bridge) - firm: Zellic date: '2025-11' scope: Dashboard and Faucet components - firm: Zellic date: '2025-12' scope: P2P - firm: Zenith date: '2025-12' scope: g16 and CKT audit_note: >- Mainnet v1 contracts are under active audit; the listed reports cover the Alpha/Testnet implementations. evidence: - source: https://docs.alpenlabs.io/community/security kind: disclosure-page keywords: [bug bounty, immunefi, security@alpenlabs.io, responsible disclosure, audits] - source: well-known/alpen-labs-security.txt kind: security.txt