1.Reporting a vulnerability
Email security@solanavibestation.com with a description of the issue, the affected URL or endpoint, the steps to reproduce, and the impact you observed. Proof-of-concept code or screenshots are welcome.
2.Scope
In scope for security research:
- Production RPC endpoints under
*.solanavibestation.com - The public web application and the customer portal
- The VPS control plane and console-proxy surface
Out of scope:
- Denial-of-service or volumetric testing of any kind
- Social-engineering or phishing of staff or customers
- Third-party services we integrate with (our payment processors and Discord) — please report issues in those platforms to their own security programs
- Recently-disclosed CVEs without a working proof-of-concept against our deployment
- Physical attacks on our facilities or staff
3.Safe harbor
Good-faith security research conducted within the scope above is authorized. We will not pursue legal action against researchers who follow this policy, give us reasonable time to remediate before public disclosure, and avoid privacy violations, data destruction, or service degradation.
4.Response targets
We aim to acknowledge reports within 5 business days and to provide an initial triage update within 15 business days. These are targets, not contractual commitments — remediation timelines depend on severity and complexity.
5.Coordinated disclosure
Default disclosure window is 90 days from the date we acknowledge the report. We may request an extension for complex fixes; we will not invoke an extension to delay disclosure of a remediated issue.
6.Bug bounty
We do not operate a paid bug bounty at this time. We will, however, acknowledge researchers who report valid issues in good faith on a case-by-case basis — reach out if you would like a write-up on our blog.
7.Abuse reporting
Report network abuse, spam, or takedown requests related to traffic originating from our infrastructure to security@solanavibestation.com. Include the source IP or hostname, timestamps with timezone, and any log evidence you can share.
8.Incident response process
- Authoritative status. status.solanavibestation.com is the system of record for incident timelines and resolution status. The incident page there governs both the SLA and the public history of the event.
- Notification channels. Operational announcements posted to our Discord are mirrored to the in-portal notification bell. For billing-impacting incidents, affected customers are notified by email. The status page is the durable record; the bell and Discord are convenience channels.
- Severity classification. SEV-1 covers a full outage or confirmed data exposure; SEV-2 covers partial degradation (e.g. one upstream provider failing or one region affected); SEV-3 covers single-customer or non-blocking issues.
- Postmortem cadence. For SEV-1 incidents, a public postmortem is published on the status page within 30 days of resolution. SEV-2 summaries are available on request to security@solanavibestation.com.