Security Research and Vulnerability Disclosure Policy
1. Purpose
OceanAlt welcomes good-faith researchers who help find API security issues, authorisation bypasses, Agent attribution flaws, replay, weaknesses in pre-payment risk controls, and privacy or data-leak issues.
2. Safe harbour
To the extent permitted by law, where a researcher acts in good faith, follows this policy, causes no actual harm to users or third parties, does not steal, publish or misuse data, does not extort, and reports promptly, OceanAlt will in principle not seek civil remedies solely for that good-faith research and will treat it as authorised security research. This safe harbour does not authorise testing of third-party systems.
3. Out of scope / prohibited
DoS/DDoS; large-scale automated scanning that degrades service; social engineering; phishing staff or users; accessing unrelated personal data; moving real assets; modifying or deleting production data; attacking third-party RPCs, wallets, facilitators or data sources; publishing exploitable details before OceanAlt has had reasonable time to fix.
4. How to report
Report security issues to business@oceanalt.com (a dedicated security mailbox will be listed here once live). Include: impact, reproduction steps, request/response, risk explanation, whether real funds or personal data are involved, and a suggested fix.
5. Response
OceanAlt will make reasonable efforts to acknowledge receipt, assess impact and provide progress in due course. High-risk payment, funds or credential issues are prioritised. No fixed SLA is promised.

