{"service":"SolMachina","policy":"Coordinated vulnerability disclosure","contact":"mailto:contact.notamob@gmail.com","canonical":"https://api.solmachina.com/security","updatedUtc":"2026-09-09T16:09:23.489Z","scope":{"inScope":["api.solmachina.com and its documented /v1/* endpoints","the x402 payment surface (402 challenge, verification, settlement)","public discovery surfaces (/.well-known/*, /openapi.json, /llms.txt, /AGENTS.md)"],"outOfScope":["denial-of-service / volumetric or rate-limit-exhaustion attacks","spam, phishing or social engineering of the operator","findings requiring physical access to infrastructure","automated scanner output with no demonstrated impact"]},"rules":["Do NOT run exploit attempts against real funds or real settlements — describe the vector instead.","Do not access, modify or destroy data that is not yours.","Give us reasonable time to remediate before any public disclosure.","Include clear reproduction steps and a concrete impact statement."],"safeHarbor":"Good-faith research consistent with this policy is welcome; we will not pursue action for accidental, good-faith violations discovered and reported responsibly.","response":{"acknowledgeTargetHours":72,"note":"Independent operator: best-effort but genuine response times."},"advisories":[],"acknowledgements":[],"encryption":null,"seeAlso":["/.well-known/security.txt","/trust/x402","/legal"]}