generated: '2026-09-19' method: searched source: https://github.com/solvela-ai/solvela/blob/main/SECURITY.md probed: - {url: 'https://github.com/solvela-ai/solvela/blob/main/SECURITY.md', status: 200, fetched: '2026-09-19'} - {url: 'https://api.solvela.ai/.well-known/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://api.solvela.ai/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://solvela-gateway.fly.dev/.well-known/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://solvela.ai/.well-known/security.txt', status: 402, fetched: '2026-09-19', note: Vercel DEPLOYMENT_DISABLED} summary: >- Solvela publishes a vulnerability disclosure policy as SECURITY.md in its public repository: report to security@solvela.ai, do not open public issues, acknowledgement within 1 hour for P0 (custody, payment, auth) and a response within 24 hours for everything else. The same file states that an RFC 9116 security.txt "is served from api.solvela.ai"; it is not — both well-known paths 404 on both API hosts as of 2026-09-19 — so the policy is findable through GitHub but not through the standard machine path. No bug bounty programme (HackerOne, Bugcrowd, Intigriti or self-run) was found, no safe-harbour language, no PGP key and no encrypted channel. The file goes unusually far in disclosing posture: the escrow program's upgrade authority (a warm single-sig key with a planned Squads multisig migration), the unified fee-payer/recipient wallet, the accepted transitive advisories with reasons, and the semantic-cache embedding caveat. probe-security-programs.py found no hit because it looks for security.txt, bounty platforms and disclosure pages on the provider's hosts; this file upgrades that result from the repository. policy: url: https://github.com/solvela-ai/solvela/blob/main/SECURITY.md contact: security@solvela.ai contact_type: email public_issues: discouraged — "Do not open public GitHub issues for security reports" acknowledgement: 1 hour for P0 (custody / payment / auth) response: 24 hours for everything else scope: gateway (api.solvela.ai), dashboard (solvela.ai, app.solvela.ai, docs.solvela.ai), escrow program on Solana mainnet, SDKs safe_harbor: not stated pgp: none published bug_bounty: none found security_txt: claimed: true served: false note: '"A .well-known/security.txt is served from api.solvela.ai" (SECURITY.md) — 404 on 2026-09-19.' disclosed_posture: escrow_program: '9neDHouXgEgHZDde5SpmqqEZ9Uv35hFcjtFEPxomtHLU on Solana mainnet; upgrade authority EDM9pao5miQdJYfzCtZii9cVn5ZHTBJq84Y9yyqZbsr4, single-sig on the operator workstation (migrated 2026-05-08 off the gateway hot wallet); Squads multisig or hardware-backed authority is the stated next step' operational_wallet: '9QGtTUpvLmhggDuBciAeE67MmhECVFYdFLD7xKD4RSno serves as both fee payer and payment recipient by design (consolidated 2026-05-29 to 05-31)' dependency_hygiene: cargo audit and npm audit pass at HEAD; a short list of accepted transitive advisories is published with reasons runtime_controls: [ed25519 signature + ATA + TransferChecked verification, replay protection (Redis SET NX EX 120), prompt-injection/jailbreak/PII guard run before any funds move, per-wallet rate limiting that ignores X-Forwarded-For, explicit CORS allowlist, secret redaction in Debug impls, SSRF checks on marketplace endpoints, constant-time admin-token comparison] data_minimisation: 'no prompt or response content is persisted; IPs only in transient rate-limit buckets and the admin audit trail (docs/product/regulatory-position.md)' a2a_task_ids: documented as bearer capabilities with a 10-minute TTL