Security and vulnerability disclosure
Report suspected vulnerabilities privately to admin@kushbitx.com. Trust Center · Security advisories · security.txt
Scope and boundaries
KushBitx SpendGuard, AgentProof, kushbitx.com and the public @kushbitx/sdk package. Third-party infrastructure, wallets, signers, payment facilitators and other organizations' software are outside our authority.
KushBitx does not hold wallet private keys, request seed phrases, sign customer transactions or execute customer payments. A separate trusted signer/payment system must enforce policy decisions.
What to report
Include the affected URL or package version, safe reproduction steps, expected and observed behavior, impact, approximate test time, and non-sensitive logs or request IDs.
Protect people, data and funds
Do not send private keys, seed phrases, payment signatures, recovery keys, administrator/API/OAuth secrets, or unrelated customer data. Do not access or modify others' data, use social engineering, disrupt service, establish persistence, exfiltrate data, or execute financial transfers to demonstrate a finding. Stop if testing encounters sensitive data or could create customer or financial impact.
Intake and triage
The KushBitx Trust & Verification executive function coordinates vulnerability and CVE handling through admin@kushbitx.com. Reports are handled through the existing operational management flow.
- Record an internal case ID, receipt time, affected component/version and reporter contact; acknowledge actionable reports when possible.
- Check ownership and duplicates, reproduce safely, and assess severity and exploitability. Escalate immediate customer or financial risk to the owner.
- Assign remediation and review; preserve restricted evidence without publishing exploit details prematurely.
- Coordinate disclosure timing, credit and, where appropriate, CVE assignment with an authorized CNA.
- Publish a dated advisory with affected/fixed versions and mitigation, then document closure and follow-up.
This is a disclosure and coordination policy. There is no promised bounty, guaranteed response time, or third-party security certification. KushBitx is not a CVE Numbering Authority.