Manav.id
Trust

Report a vulnerability.

If you have found a weakness in the protocol, the verifier or this site, we want to hear about it before anyone else does.

Last updated 24 September 2026

How to reach us

What we commit to

CommitmentTarget
Acknowledge your report3 business days
Initial assessment and severity10 business days
Coordinated disclosure window90 days from acknowledgement
Credit in the advisoryYes, unless you ask us not to
We do not currently run a paid bug bounty. We are saying so rather than leaving it ambiguous.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your work as authorised under applicable computer-misuse law.

Good faith means: do not access, modify or destroy data that is not yours; do not degrade the service; do not use social engineering or physical attacks; give us a reasonable window before publishing.

In scope

Out of scope: findings that require a compromised authenticator or a compromised host display — we already state those limits in the whitepaper's security considerations. Volumetric denial of service. Reports generated solely by an automated scanner with no demonstrated impact.