Skip to content

Security: AureumDCA/dca-vault-contract

Security

SECURITY.md

Security Policy

Scope

AureumDCA's dca-vault-contract is a Soroban smart contract currently deployed on Stellar Testnet only. It has not been audited and is not intended for use with real funds on Mainnet at this stage.

Reporting a Vulnerability

If you discover a security vulnerability in this contract — including but not limited to issues affecting fund safety, authorization checks, the swap execution atomicity guarantee, or the schedule state machine — please report it privately rather than opening a public GitHub issue.

To report: email douglasfrancis054@gmail.com with a clear description of the vulnerability, steps to reproduce if applicable, and its potential impact.

Please do not disclose the vulnerability publicly (including in GitHub issues, pull requests, or Discord) until it has been reviewed and, if valid, addressed.

What to expect

  • We aim to acknowledge reports within 5 business days.
  • We will keep you updated as we investigate and, if applicable, work on a fix.
  • Once resolved, we're happy to credit reporters in the fix's commit message or release notes, unless you prefer to remain anonymous.

Out of scope

  • Issues already tracked in open GitHub issues
  • Purely theoretical vulnerabilities with no demonstrated impact
  • Issues in third-party dependencies (report those to the respective maintainers; we will still appreciate a heads-up)

There aren't any published security advisories