OceanAltOceanAlt

Security Research and Vulnerability Disclosure Policy

Document version V0.1Legal set V0.4Effective 2026-09-12business@oceanalt.com

This is the bilingual V0.4 publication copy of the OceanAlt legal documents. OceanAlt is at an early stage and has not yet designated a single formal legal operating entity; these documents use a transitional operating arrangement and do not fabricate any legal-entity details.

Core reminder: no risk signal found ≠ safe. Pre-payment screening does not replace your own authorisation, transaction monitoring, legal judgement or necessary human review.

1. Purpose

OceanAlt welcomes good-faith researchers who help find API security issues, authorisation bypasses, Agent attribution flaws, replay, weaknesses in pre-payment risk controls, and privacy or data-leak issues.

2. Safe harbour

To the extent permitted by law, where a researcher acts in good faith, follows this policy, causes no actual harm to users or third parties, does not steal, publish or misuse data, does not extort, and reports promptly, OceanAlt will in principle not seek civil remedies solely for that good-faith research and will treat it as authorised security research. This safe harbour does not authorise testing of third-party systems.

3. Out of scope / prohibited

DoS/DDoS; large-scale automated scanning that degrades service; social engineering; phishing staff or users; accessing unrelated personal data; moving real assets; modifying or deleting production data; attacking third-party RPCs, wallets, facilitators or data sources; publishing exploitable details before OceanAlt has had reasonable time to fix.

4. How to report

Report security issues to business@oceanalt.com (a dedicated security mailbox will be listed here once live). Include: impact, reproduction steps, request/response, risk explanation, whether real funds or personal data are involved, and a suggested fix.

5. Response

OceanAlt will make reasonable efforts to acknowledge receipt, assess impact and provide progress in due course. High-risk payment, funds or credential issues are prioritised. No fixed SLA is promised.

Other documents: Legal centre →