Security & Vulnerability Disclosure
How to report a security issue responsibly.
Last updated: July 11, 2026
1. Reporting
If you discover a vulnerability, please report it privately to the security contact and allow reasonable time to remediate before public disclosure. Do not exploit the issue or access data that is not yours.
2. Scope
The Touki websites, explorer, RPC, and official smart contracts are in scope. Social engineering and denial-of-service testing are out of scope.
Update this policy with your security email or disclosure platform and any bug-bounty details.