generated: '2026-09-17' method: searched source: https://github.com/celestiaorg/.github/blob/main/SECURITY.md description: >- Celestia Labs publishes a written security policy covering the whole @celestiaorg GitHub organization and its related infrastructure. It is served as an org-level SECURITY.md rather than at /.well-known/security.txt — the RFC 9116 path 404s on every Celestia host probed — so it is discoverable to a human reading a repository and invisible to a machine walking well-known paths. program_published: true policy_url: https://github.com/celestiaorg/.github/blob/main/SECURITY.md raw_policy: celestia-security-policy.md contact: preferred_channel: GitHub Security Advisory on the affected repository email: security@celestia.org email_note: Fallback for repositories without security reporting configured. scope: >- Code repositories under the @celestiaorg GitHub organization and any related infrastructure. disclosure_policy: coordinated: true embargo_days: 120 terms: >- A reporter may share details with third parties once the vulnerability is fixed and the program owner permits disclosure, or 120 days after submission, whichever comes first. communication_channel: Security advisories on the affected repository. safe_harbor: true safe_harbor_note: >- The policy explicitly extends safe harbour for research conducted under it, and commits to a timely initial response, validation with the reporter, and timely remediation. bug_bounty: offered: false platform: null note: >- Stated plainly in the policy: "Celestia Labs has no formal reward policy and researchers should not expect a reward for discovering a vulnerability." Acknowledgement after a fix is widely deployed is the only recognition offered. supported_versions: >- Most recent minor version release, unless otherwise specified. security_txt: published: false probed_hosts: - host: celestia.org status: 404 - host: www.celestia.org status: 404 - host: docs.celestia.org status: 404 - host: blog.celestia.org status: 404 - host: forum.celestia.org status: 404 note: >- A one-file fix worth suggesting to the provider: the policy and the contact address already exist, so an RFC 9116 security.txt at celestia.org would cost nothing and would make an existing program machine-discoverable.