Corso @CorsoHQ

Security policy

Corso is a trading app for Solana. A bug here can cost someone money or expose the keys that control it, so we would much rather hear about it from you than from a user. If you have found something, tell us. The process below is short on purpose.

Contact: support@corso.trade — put SECURITY at the start of the subject line so it is triaged as a report and not as a support ticket.

This policy is published by Dinario Technologies Inc. and covers the Corso mobile app and the services it talks to.

How to report

Email us with enough to reproduce the issue: what you did, what happened, what you expected, and the build you were on (Corso → Account → About & legal shows the version). A proof-of-concept, a stack trace, a screen recording, or a transaction signature all help. Please write in English if you can.

Report privately and give us a chance to fix it before you publish. Please do not open a public issue, post it, or disclose it to a third party first.

If you believe the issue is being actively exploited, say so in the first line of the email.

What we commit to

Acknowledge your reportwithin 3 business days
First substantive assessmentwithin 10 business days
Fix or a dated remediation plan for a confirmed critical issuewithin 90 days
Keep you updatedat least every 14 days while the report is open

We will tell you honestly if we think a report is not a vulnerability, and why. If you disagree, say so — we would rather re-examine it.

We are a small team. If a deadline above is going to slip we will tell you before it slips, not after.

Scope

In scope

Issues we are especially interested in: anything that exposes or exfiltrates private key material or a recovery phrase; anything that gets a transaction signed or broadcast without the user's genuine approval, or that changes what a transaction does after the user has approved it; anything that bypasses the app lock, biometric gate, or MFA step-up; anything that lets one user reach another user's data; and anything that misrepresents an amount, a fee, a destination, or a token in the approval path.

Out of scope

Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorized. We will not bring or support legal action against you for that research, except where the law requires us to respond (for example, to a subpoena or court order), and if a third party brings action against you for work that stayed inside this policy, we will make it known that your research was authorized.

"Good faith" means, concretely:

This is our authorization, not a waiver of anyone else's rights: it does not authorize you to act against third-party services, and it does not override laws that apply to you.

Rewards

Corso does not currently run a paid bug bounty. We are not going to imply one. If that changes it will be announced here first.

What we do offer: a real answer from a person, credit in the release notes and in a security acknowledgements list if you want it (tell us the name or handle to use, or ask to stay anonymous), and — for a report that materially protects users — a discretionary thank-you that we will discuss with you directly. None of that is a contractual entitlement, and we will never make you agree to anything in order to receive an acknowledgement.

Also published at

The machine-readable pointer to this policy is at https://corso.trade/.well-known/security.txt.