generated: '2026-09-04' method: searched probe: true source: >- https://braiins.com/security (published vulnerability disclosure policy), https://braiins.com/.well-known/security.txt (RFC 9116) program: type: coordinated-disclosure bug_bounty: false bounty_note: >- Braiins offers public credit at the reporter's option, not a monetary bounty. No HackerOne, Bugcrowd or Intigriti program was found. policy_url: https://braiins.com/security security_txt: https://braiins.com/.well-known/security.txt security_txt_expires: '2027-08-31' contact: - mailto:security@braiins.com encryption: pgp_key: https://braiins.com/security/pgp.asc fingerprint: D120 E69A 68F8 C228 20FB FD3B 5FAC 1904 B64C 9C23 alternate_channel: >- Signal, arranged on request — Braiins asks for a first message with no technical detail. preferred_languages: - en - cs commitments: - id: first-reply text: A human reply from a named person within 5 business days. binding: true - id: safe-harbour text: No legal action for good-faith research, within the stated safe-harbour limits. binding: true - id: triage-transparency text: Braiins states whether it accepts the report, the severity assigned, and the intended fix. binding: false - id: coordinated-publication text: Publication date and wording agreed with the reporter; Braiins does not publish the finding as its own. binding: false - id: no-fix-sla text: >- Braiins explicitly declines to commit to a fix deadline, citing firmware release cadence and hardware-vendor dependencies. binding: false severity_classes: - name: Critical definition: >- Loss or theft of funds, or a compromise that scales across a fleet or across accounts without per-target effort. examples: - Signing or payout manipulation in Braiins Pool - Order or settlement manipulation in Braiins Hashpower - Remote code execution on mining devices reachable at scale - Installation of unsigned or modified firmware on a device the attacker does not physically control - name: High definition: >- Compromise of a single device or account with significant impact, or a break of a security control protecting funds or credentials. examples: - Authentication bypass on a miner's management interface - Extraction of stored pool credentials or licence secrets - name: Medium definition: Recorded on the policy page; not transcribed here. - name: Low definition: Recorded on the policy page; not transcribed here. reporting_rules: - Do not open a public issue, pull request, support ticket or forum post for a security issue. - Include impact, affected product and version (exact firmware build or URL), reproduction steps, and a PoC. - Reports accepted in English or Czech. entity_note: >- The policy is given by Braiins Systems s.r.o. and its Affiliates; a report is handled by the Affiliate that operates the product concerned, and Braiins says it will name that entity. evidence: - source: https://braiins.com/security kind: published vulnerability disclosure policy http_status: 200 fetched: '2026-09-04' - source: well-known/braiins-academy-security.txt kind: RFC 9116 security.txt served from https://braiins.com/.well-known/security.txt http_status: 200 fetched: '2026-09-04'