Products
Open-source
Restaking
dApp
Enterprise Dashboard
Validators
Connect
On-Chain
DeFi
Solutions
Protocols
STAKING
Docs
Products
DEFI
Solutions
Protocols
STAKING
Docs

This Vulnerability Disclosure Policy outlines the process through which individuals can report vulnerabilities found within our systems, networks, or services. We recognize the value of the security community's efforts in helping us secure our services and are committed to addressing all reported vulnerabilities in a timely manner.

For smart contracts vulnerabilities, Kiln operates dedicated programs with their own reward structure:
The rest of this policy focuses on the scope detailed further down.


Under this policy, "research" means activities in which you:
Once you've established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

The following testing and reporting activities are strictly prohibited:

Smart contract scope and testing guidelines are managed directly on Cantina, where each program defines its own in-scope contracts, exclusions and rules:

Reward amounts for smart contract vulnerabilities are set and paid out per program on Cantina, based on severity and impact:

We only accept vulnerability reports through Cantina. Please submit your findings directly on the relevant program page:
Reports sent to security@kiln.fi will no longer be monitored or accepted.

In order to help us triage and prioritize submissions, we require that your reports:

When you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.

This policy is subject to periodic review and may be updated or modified at any time by Kiln without prior notice.

Questions regarding this policy may be sent to security@kiln.fi. We also invite you to contact us with suggestions for improving this policy.