Full policy, audit status, scope, and safe-harbour terms:
docs.so4.market/resources/security
(source: apps/docs/content/resources/security.mdx)
- SO4's Soroban contracts have not been audited by a third party.
Current deployments are testnet-only — see
apps/docs/content/reference/contracts.generated.mdx. - Do not open a public GitHub issue for a suspected vulnerability.
- Report privately to the maintainer: t.me/ibrahimijai.
- You will never be asked for your secret key, seed phrase, or any wallet credential to report or verify a vulnerability.
- There is no bug bounty program at this time.
See the linked page for full scope, response-time expectations, safe-harbour terms, and known limitations.