Report a vulnerability.
If you have found a weakness in the protocol, the verifier or this site, we want to hear about it before anyone else does.
Last updated 24 September 2026
How to reach us
- Email [email protected].
- Machine-readable: /.well-known/security.txt (RFC 9116).
What we commit to
| Commitment | Target |
|---|---|
| Acknowledge your report | 3 business days |
| Initial assessment and severity | 10 business days |
| Coordinated disclosure window | 90 days from acknowledgement |
| Credit in the advisory | Yes, unless you ask us not to |
Safe harbour
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your work as authorised under applicable computer-misuse law.
Good faith means: do not access, modify or destroy data that is not yours; do not degrade the service; do not use social engineering or physical attacks; give us a reasonable window before publishing.
In scope
- The receipt, statement and lease constructions, and the verifier.
- manav.id and its subdomains.
- The published SDKs and verifier packages.
Out of scope: findings that require a compromised authenticator or a compromised host display — we already state those limits in the whitepaper's security considerations. Volumetric denial of service. Reports generated solely by an automated scanner with no demonstrated impact.