For the complete documentation index, see llms.txt. This page is also available as Markdown.

Responsible Disclosure

How to report a security vulnerability in Rome Protocol responsibly — contact channels, what to include, and disclosure guidelines.

If you discover a security vulnerability in Rome Protocol, please report it responsibly.

Reporting

Email rome@romeprotocol.com, or open a ticket in the Rome Discord to reach the core team privately.

What to include:

  • Description of the vulnerability

  • Steps to reproduce

  • Potential impact assessment

  • Your contact information for follow-up

Guidelines

  • Do not publicly disclose the vulnerability before a fix is deployed

  • Do not exploit the vulnerability beyond what is necessary to demonstrate it

  • Do not access or modify data belonging to other users

  • Allow reasonable time for the team to investigate and fix the issue

Scope

In scope:

  • Rome EVM on-chain program

  • Rome Proxy and Hercules services

  • Rome Solidity SDK and contract libraries

  • Oracle Gateway adapters

  • Bridge contracts (ERC20SPL, Factory)

Out of scope:

  • Third-party dependencies (report to their maintainers)

  • Social engineering attacks

  • Denial of service against testnet/devnet infrastructure

  • Issues in deprecated or archived repositories

Community

  • Discord — general questions and support

  • Telegram — community updates

  • GitHub — code and issue tracking

Last updated

Was this helpful?