Our Responsible Disclosure Policy provides clear guidelines for submitting reports through our support portal, ensuring confidentiality.
At Xahau, we believe that the security of our systems is extremely important.
Despite our concern for the security of our systems during product development and maintenance, there's always the possibility of someone finding something we need to improve/update/change/fix /...
We appreciate you notifying us if you have found a weak point in one of our systems as soon as possible so we can immediately take measures to protect our customers and their data.
If you believe you have found a security issue in one of our systems, please notify us as soon as possible by posting a high level description of your finding and contact information (so someone can reach out) on Github: https://github.com/Xahau/xahaud/issues
This responsible disclosure policy is not an open invitation to actively scan our network and applications for vulnerabilities. Our continuous monitoring will likely detect your scan, and these will be investigated.
Not share information about the security issue with others until the problem is resolved, and to immediately delete any confidential data acquired
Not further abuse the problem, for example, by downloading more data than is necessary to demonstrate the leak or to view, delete, or amend the data of third parties
Provide detailed information in order for us to reproduce, validate, and resolve the problem as quickly as possible. Include your test data, timestamps, and URL(s) of the system(s) involved
Leave your contact details (e-mail address and/or phone number) so that we may contact you about the progress of the solution. We do accept anonymous reports.
Do not use attacks on physical security, social engineering, distributed denial of service, spam, or applications of third parties
You will receive a confirmation of receipt from us within 4 working days after the report is made
You will receive a response with the assessment of the security issue and an expected date of resolution within 4 working days after the confirmation of receipt is sent
We will take no legal steps against you in relation to the report if you have kept to the conditions as set out above
We will handle your report confidentially, and we will not share your details with third parties without your permission unless that is necessary in order to fulfill a legal obligation
Complaints
Website unavailable reports
Phishing reports
Fraud reports
For these complaints or reports, please post a high level description of your issue and contact information (so someone can reach out) on Github: https://github.com/Xahau/xahaud/issues
Xahau encourages the reporting of security issues or vulnerabilities. We may make an appropriate reward for confidential disclosure of any design or implementation issue that could be used to compromise the confidentiality or integrity of our users' data that was not yet known to us. We decide whether the report is eligible and the amount of the reward.
(D)DOS attacks
Error messages or error pages without sensitive data
Tests & sample data as publicly available in our repositories on Github
Common issues like browser header warnings or DNS configuration, identified by vulnerability scans
Vulnerability scan reports for the software we publicly use
Security issues related to outdated OS's, browsers, or plugins
Reports for security problems that we have been notified of before
Please note: Reports that lack any proof (such as screenshots or other data), detailed information, or details on how to reproduce any unexpected result will be investigated but will not be eligible for any reward.
This policy is based on the National Cyber Security Centre’s Responsible Disclosure Guidelines and an example by Floor Terra.
The Hooks amendment, integral to XRPL's smart contract infrastructure, has passed a detailed security audit by FYEO. The audit examined the Hooks framework implementation, including the Hook API, helper functions, and execution environment.
With no severe security issues detected and all minor issues resolved, this audit serves as a testament to our commitment to security and the robustness of Hooks.
By enabling smart transaction logic directly on XRPL's Layer 1, Hooks bring increased flexibility to tailor applications to their unique needs, inspiring further innovation within the XRPL ecosystem.
Developers now have robust tools for creating and deploying custom logic, accessible on our testnet.
The audit's successful completion is not just a milestone but a cornerstone for the ongoing security and sustainability of the Hooks network.
With all identified vulnerabilities addressed, the Hooks amendment is set to drive innovation securely on Xahau.
To a brighter, more innovative future with Xahau!