generated: '2026-09-19' method: searched probe: true source: https://cymetica.com/.well-known/security.txt policy: - https://cymetica.com/contact contact: - https://cymetica.com/contact - https://t.me/vsbcorp evidence: - source: https://cymetica.com/.well-known/security.txt kind: security.txt (live probe) - source: https://cymetica.com/bug-bounty kind: bug bounty page (live, 200) - source: https://cymetica.com/security kind: redirects to /bug-bounty bug_bounty: url: https://cymetica.com/bug-bounty program: self-hosted (no HackerOne/Bugcrowd/Intigriti) scope: '"Report bugs of all types" — platform, trading, API, smart contracts, docs' rewards: currency: CYM token critical: 400,000 - 1,000,000 CYM (fund theft, outage, contract drainage, data loss) high: 100,000 - 400,000 CYM medium: 25,000 - 100,000 CYM (incl. "API returning incorrect data") low: 5,000 - 25,000 CYM (incl. documentation inaccuracies) maximum: 1,000,000 CYM vesting: 25% at TGE, 75% linear over 6 months; soulbound vesting NFT; BugBountyVesting contract 0xb693e3DffDe0a05C1dD509f7a5fff2358b1DC669 (Base) response_time: 'Our team reviews within 48 hours (page: "48h Avg Response Time")' submission: Web form on the page (no sign-up; wallet address for payout); also MCP tool get_bug_bounty_program and the agent card's bounty endpoints (POST /api/v1/bounty/qa-agent/ask) note: The A2A card's bug-bounty skill says awards are a flat ET10 amount per verified bug while the page says tiered CYM — two descriptions of one programme; recorded as published, not reconciled. security_txt: contact: - https://cymetica.com/contact - https://t.me/vsbcorp expires: '2026-12-31T23:59:00.000Z' policy: https://cymetica.com/contact canonical: https://cymetica.com/.well-known/security.txt note: 'Policy: points at the generic contact page, not a disclosure policy; the substantive programme is /bug-bounty (/security 302s there).'