Published 27 September 2026

Security and vulnerability disclosure

Report suspected vulnerabilities privately to admin@kushbitx.com. Trust Center · Security advisories · security.txt

Scope and boundaries

KushBitx SpendGuard, AgentProof, kushbitx.com and the public @kushbitx/sdk package. Third-party infrastructure, wallets, signers, payment facilitators and other organizations' software are outside our authority.

KushBitx does not hold wallet private keys, request seed phrases, sign customer transactions or execute customer payments. A separate trusted signer/payment system must enforce policy decisions.

What to report

Include the affected URL or package version, safe reproduction steps, expected and observed behavior, impact, approximate test time, and non-sensitive logs or request IDs.

Protect people, data and funds

Do not send private keys, seed phrases, payment signatures, recovery keys, administrator/API/OAuth secrets, or unrelated customer data. Do not access or modify others' data, use social engineering, disrupt service, establish persistence, exfiltrate data, or execute financial transfers to demonstrate a finding. Stop if testing encounters sensitive data or could create customer or financial impact.

Intake and triage

The KushBitx Trust & Verification executive function coordinates vulnerability and CVE handling through admin@kushbitx.com. Reports are handled through the existing operational management flow.

  1. Record an internal case ID, receipt time, affected component/version and reporter contact; acknowledge actionable reports when possible.
  2. Check ownership and duplicates, reproduce safely, and assess severity and exploitability. Escalate immediate customer or financial risk to the owner.
  3. Assign remediation and review; preserve restricted evidence without publishing exploit details prematurely.
  4. Coordinate disclosure timing, credit and, where appropriate, CVE assignment with an authorized CNA.
  5. Publish a dated advisory with affected/fixed versions and mitigation, then document closure and follow-up.

This is a disclosure and coordination policy. There is no promised bounty, guaranteed response time, or third-party security certification. KushBitx is not a CVE Numbering Authority.

KushBitx AgentProof · Crypto trust API for people and agentsDeveloper quickstartPricingTrust Center