generated: '2026-09-19' method: searched source: https://docs.execution.market/project/security checked: '2026-09-19' summary: >- Execution Market publishes a vulnerability-reporting page in its docs with a dedicated security mailbox, a stated acknowledgement SLA and an explicit safe-harbour commitment for good-faith researchers. There is no RFC 9116 security.txt on any host (probe-security-programs.py therefore found nothing) and no formal bug bounty — the page says one is being "explored". Recorded as a real, provider-published disclosure policy; NOT as a bounty program. program: type: responsible-disclosure contact: security@execution.market url: https://docs.execution.market/project/security policy_statement: 'Do NOT open a public GitHub issue for security vulnerabilities. Instead, email security@execution.market' report_contents: [description of the vulnerability, steps to reproduce, potential impact, contact information (optional)] acknowledgement_sla: 'We respond within 48 hours and provide updates as we investigate' resolution_target: 'We aim to resolve critical issues within 7 days' safe_harbor: 'We do not pursue legal action against good-faith security researchers' credit: 'We give credit (if desired) in our security changelog' bug_bounty: exists: false platform: null statement: 'We are exploring a formal bug bounty program. Contact security@execution.market to discuss.' security_txt: served: false probed: [https://api.execution.market/.well-known/security.txt, https://mcp.execution.market/.well-known/security.txt, https://auth.execution.market/.well-known/security.txt, https://docs.execution.market/.well-known/security.txt] note: 404 on every real host; execution.market/www answer the SPA shell (not a document). No SecurityTxt pointer. published_controls: authentication: [ERC-8128 wallet-signed requests, wallet_session, OAuth 2.1 for MCP clients, X-Admin-Key for admin panel] secrets: AWS Secrets Manager, injected at ECS task start, private keys never logged blockchain: EIP-3009 authorizations bound to amount/recipient/deadline/nonce; PaymentOperator StaticAddressCondition; immutable x402r contracts evidence: presigned S3 uploads, CloudFront signed URLs, server-side EXIF GPS validation database: Supabase row-level security on all tables, parameterized queries api: rate limiting per IP and API key, CORS allow-list, Pydantic v2 validation ci_scanning: [CodeQL, Semgrep, Trivy, Gitleaks, Bandit, Safety] known_limitations_disclosed: [GPS anti-spoofing is a soft signal, AI verification can be fooled — agent approval always required, wallet private-key custody is the user's] contract_audits: url: https://docs.execution.market/contracts/audits note: five audit rounds summarised for the LEGACY escrow v1.4.0 (now deprecated); auditor not named; the live x402r contracts are described as "audited, deployed" in skill/reference/streams.md without a linked report