generated: '2026-07-18' method: searched probe: false source: https://docs.common.xyz/commonwealth/community-overview-3/developers.md contact: - security@common.xyz policy: [] summary: >- Common (Commonwealth) publishes a security contact for vulnerability disclosure in its developer documentation, directing reporters to email security@common.xyz. No formal bug-bounty program (HackerOne / Bugcrowd / Intigriti), no /.well-known/security.txt (the host serves a SPA fallback for that path), and no dedicated responsible-disclosure policy page were found. evidence: - source: https://docs.common.xyz/commonwealth/community-overview-3/developers.md kind: docs-security-contact detail: "For vulnerability disclosures, developers should contact security@common.xyz"