Security policy
Corso is a trading app for Solana. A bug here can cost someone money or expose the keys that control it, so we would much rather hear about it from you than from a user. If you have found something, tell us. The process below is short on purpose.
Contact: support@corso.trade — put SECURITY at the start of the subject line so it is triaged as a report and not as a support ticket.
This policy is published by Dinario Technologies Inc. and covers the Corso mobile app and the services it talks to.
How to report
Email us with enough to reproduce the issue: what you did, what happened, what you expected, and the build you were on (Corso → Account → About & legal shows the version). A proof-of-concept, a stack trace, a screen recording, or a transaction signature all help. Please write in English if you can.
Report privately and give us a chance to fix it before you publish. Please do not open a public issue, post it, or disclose it to a third party first.
If you believe the issue is being actively exploited, say so in the first line of the email.
What we commit to
| Acknowledge your report | within 3 business days |
| First substantive assessment | within 10 business days |
| Fix or a dated remediation plan for a confirmed critical issue | within 90 days |
| Keep you updated | at least every 14 days while the report is open |
We will tell you honestly if we think a report is not a vulnerability, and why. If you disagree, say so — we would rather re-examine it.
We are a small team. If a deadline above is going to slip we will tell you before it slips, not after.
Scope
In scope
- The Corso mobile app (iOS
app.corso.wallet, Androidapp.corso.wallet, Solana dApp Storecom.dinario.app) — current released builds. - The Corso API and the hosted config it serves.
corso.tradeand its subdomains, where they are operated by Dinario.- The Corso app's source code, including its build and release configuration.
Issues we are especially interested in: anything that exposes or exfiltrates private key material or a recovery phrase; anything that gets a transaction signed or broadcast without the user's genuine approval, or that changes what a transaction does after the user has approved it; anything that bypasses the app lock, biometric gate, or MFA step-up; anything that lets one user reach another user's data; and anything that misrepresents an amount, a fee, a destination, or a token in the approval path.
Out of scope
- Third-party services we integrate but do not run — Privy, Jupiter, MoonPay, RPC providers, the Solana network itself. Report those to their own programs; tell us too if it affects Corso users.
- Findings that are only a scanner's output, with no demonstrated impact: missing security headers, absent SPF/DMARC on non-mail subdomains, TLS configuration nits, version-disclosure banners, and similar.
- Social engineering of Dinario staff or users, physical attacks, and anything requiring a stolen or already-compromised device with the attacker holding the user's unlock credential.
- Denial of service, volumetric or otherwise, and any load testing.
- Self-inflicted outcomes: a user who is phished into revealing their own recovery phrase, or who approves a malicious transaction after Corso has shown them what it does.
- Bugs in a build we no longer ship.
Safe harbor
If you make a good-faith effort to follow this policy, we will treat your research as authorized. We will not bring or support legal action against you for that research, except where the law requires us to respond (for example, to a subpoena or court order), and if a third party brings action against you for work that stayed inside this policy, we will make it known that your research was authorized.
"Good faith" means, concretely:
- You only touch accounts and funds you control. Use your own Corso account and your own funds, on devnet or with a small mainnet balance.
- You do not access, modify, retain, or exfiltrate another person's data or funds. If you encounter someone else's data by accident, stop, do not save it, and tell us what you saw.
- You do not degrade the service for anyone else — no denial of service, no spam, no automated scanning heavy enough to matter.
- You use the minimum access needed to demonstrate the issue, and you stop as soon as you have demonstrated it.
- You give us a reasonable window to remediate before disclosing publicly, and you coordinate the timing with us.
This is our authorization, not a waiver of anyone else's rights: it does not authorize you to act against third-party services, and it does not override laws that apply to you.
Rewards
Corso does not currently run a paid bug bounty. We are not going to imply one. If that changes it will be announced here first.
What we do offer: a real answer from a person, credit in the release notes and in a security acknowledgements list if you want it (tell us the name or handle to use, or ask to stay anonymous), and — for a report that materially protects users — a discretionary thank-you that we will discuss with you directly. None of that is a contractual entitlement, and we will never make you agree to anything in order to receive an acknowledgement.
Also published at
The machine-readable pointer to this policy is at https://corso.trade/.well-known/security.txt.