> For the complete documentation index, see [llms.txt](https://docs.raxprotocol.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.raxprotocol.xyz/security/responsible-disclosure.md).

# Responsible Disclosure

RAX Protocol is committed to the responsible disclosure and remediation of security vulnerabilities.

***

#### Scope <a href="#id-577ef64e-b0af-4e08-b381-de865d8a4a38" id="id-577ef64e-b0af-4e08-b381-de865d8a4a38"></a>

Responsible disclosure applies to vulnerabilities in RAX Protocol smart contracts, the vault and strategy adapter system, API and data handling, allocation and risk engine logic, and user-facing applications.

Issues affecting external protocols (Aave, Compound, etc.) should be reported to their respective maintainers.

#### How to Report <a href="#e02cade9-f82e-48ae-b7d0-81822f215a16" id="e02cade9-f82e-48ae-b7d0-81822f215a16"></a>

If you believe you have identified a security vulnerability, please report it privately. Reports should include a clear description, steps to reproduce, potential impact assessment, and any relevant proof of concept.

Do not publicly disclose vulnerabilities before remediation or coordination.

#### Process <a href="#id-45613b87-3795-4f6a-bf31-3e632db0ae0d" id="id-45613b87-3795-4f6a-bf31-3e632db0ae0d"></a>

Upon receiving a report, RAX will acknowledge receipt, assess severity and impact, work to validate and remediate, and coordinate disclosure timing. All reports are handled promptly.

#### Bug Bounty <a href="#id-6b2e42bc-d17e-4b53-a529-89d1edf7a434" id="id-6b2e42bc-d17e-4b53-a529-89d1edf7a434"></a>

A formal bug bounty program may be introduced in the future. Until then, responsible disclosure is encouraged and recognition may be provided on a case-by-case basis.
