> For the complete documentation index, see [llms.txt](https://emeditweb.gitbook.io/pulsar-stellar-sdk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://emeditweb.gitbook.io/pulsar-stellar-sdk/governance/security.md).

# Security Policy

This page explains how to report a security problem in the Pulsar Stellar toolkit and what happens next. Each code repository carries its own `SECURITY.md`, which is the authoritative version for that repository. Where this page and a repository's `SECURITY.md` differ, the repository wins.

* [pulsar-core SECURITY](https://github.com/pulsar-stellar/pulsar-core/blob/main/SECURITY.md)
* [pulsar-app SECURITY](https://github.com/pulsar-stellar/pulsar-app/blob/main/SECURITY.md)

## Audit status

**This code is unaudited. Do not use it to custody real value.**

No third-party security audit has been performed on any Pulsar repository. The SDK builds unsigned transactions and hands them back to the caller; it does not sign transactions or hold keys. The reference contract holds no real assets and its balance tracking is a fixture, not a ledger. A security review of the decoder crate is planned for `v1.0.0-contracts`, and the `pulsar-core` policy records the result when it happens. Deployments before the `v1.0.0` line target Stellar testnet only.

## Report privately, and to the right repository

Report through GitHub, not in a public issue and not in the Telegram group. Open the affected repository's **Security** tab and choose **Report a vulnerability**. The report stays private between you and the maintainers until an advisory is published.

Route the report by the surface it affects:

| Affected surface                                                                                    | Report against                                                        |
| --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| TypeScript SDK, Go indexer and its HTTP API and database, web explorer, app CI, app dependency pins | [pulsar-app](https://github.com/pulsar-stellar/pulsar-app/security)   |
| Reference contract, decoder crate, contract build and deploy scripts, core CI, core dependency pins | [pulsar-core](https://github.com/pulsar-stellar/pulsar-core/security) |
| Stellar protocol, `@stellar/stellar-sdk`, `github.com/stellar/go`, `soroban-sdk`, Stellar RPC       | Stellar Development Foundation                                        |
| This documentation site                                                                             | [pulsar-docs](https://github.com/pulsar-stellar/pulsar-docs/issues)   |

Include what you have: which surface is affected, what an attacker gains, steps to reproduce (a failing test, a triggering request, or a testnet transaction hash is ideal), and the affected version, commit SHA, or deployed URL or contract ID.

## Response targets

These are targets, not guarantees, while the project is solo-maintained.

| Stage                                                               | Target          |
| ------------------------------------------------------------------- | --------------- |
| Acknowledge receipt                                                 | 3 working days  |
| Initial assessment                                                  | 10 working days |
| Fix or documented mitigation for a confirmed high or critical issue | 30 days         |

If a report goes unacknowledged past the first target, escalate by opening a public issue that says a security report is awaiting acknowledgement. Put no vulnerability details in it.

## What counts as a vulnerability

* **Indexer.** SQL injection, an endpoint that returns data across a boundary it should not cross, a missing or bypassable rate limit, unbounded memory growth from an attacker-controlled request, a panic reachable from an HTTP request, or contract event data trusted into the database without validation.
* **SDK.** A response from the indexer or RPC parsed without validation, a secret written to logs, or an input that crashes rather than raising a typed `PulsarError`.
* **Web explorer.** Cross-site scripting through rendered contract data, server-side request forgery through a user-supplied URL, or a secret exposed through a `NEXT_PUBLIC_` variable that should have stayed server-side.
* **Contract.** A missing or incorrect `require_auth`, an arithmetic overflow or underflow reachable from a public function, a storage entry made permanently unreachable through TTL mishandling, a state transition that violates the contract source specification, or any input that panics instead of returning a typed error.
* **Decoder.** Any input that panics, allocates without bound, or fails to terminate. The decoder guarantees an error variant on every decode failure, so a panic on malformed input is a bug.
* **Any repository.** A committed credential, a dependency pinned to a version with a known advisory, or a CI configuration that lets an untrusted pull request reach repository secrets.

A testnet deployment that can be drained is in scope as a contract-logic finding and out of scope as loss of value, because testnet assets carry no value. Findings that require a maintainer to run untrusted code or hand over credentials are out of scope.

## Disclosure

Coordinated disclosure. Once a fix ships, a GitHub Security Advisory is published naming the reporter, unless the reporter asks to stay anonymous.

There is no bug bounty. The project has no funding to pay for one, and saying otherwise would be dishonest.

## Credentials

Secrets never enter any repository. Placeholder-only `.env.example` files, a gitignored `.env.local`, deployer keys in the Stellar CLI identity store or CI secrets, and mainnet keys on a hardware wallet. If a credential reaches a commit, the response is to rotate it, not merely to remove the commit.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://emeditweb.gitbook.io/pulsar-stellar-sdk/governance/security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
