Security
Vulnerability disclosure policy, safe harbor, security-by-design, and security.txt for Rug Munch Media LLC.
We take the security of our applications seriously.
Rug Munch Media builds open-source software that protects retail crypto investors. The security of that software is fundamental to our mission. We develop in the open because we believe transparent code, reviewed by the community, is more secure than closed-source alternatives.
If you discover a security vulnerability in any Rug Munch Media product or infrastructure, we want to hear from you.
Report a Vulnerability
Email: security@cryptorugmunch.com
PGP Key: Available on request.
Please include:
- A detailed description of the vulnerability
- Steps to reproduce the issue
- Affected product(s) and version(s)
- Your assessment of severity
- Any suggested remediation (if known)
We will acknowledge your report within 48 hours and provide a timeline for resolution within 5 business days.
Scope
In Scope
- All websites operated by Rug Munch Media LLC (cryptorugmunch.com, rugmunch.io, pryscraper.com, degenfeed.xyz, walletpress.cc)
- Our self-hosted Forgejo instance (git.rugmunch.io)
- Our MCP servers and API endpoints
- The RugMunchBot Telegram bot
- Infrastructure directly operated by us (DNS, CDN configuration, mail server)
Out of Scope
- Vulnerabilities in third-party services we don’t operate (blockchain networks, Telegram, Cloudflare) — report to the respective provider
- Vulnerabilities requiring physical access to our servers
- Social engineering of our team members
- Denial of service via volumetric attacks (we have Cloudflare DDoS protection)
- Findings from automated tools without manual verification
- Bugs in open-source dependencies — report upstream, and we’ll patch on our end
Safe Harbor
We will not initiate or support legal action against security researchers who:
- Act in good faith — you’re testing to improve security, not to exploit users
- Give us reasonable time to investigate and patch before public disclosure (90 days minimum)
- Don’t exploit the vulnerability beyond what’s necessary to demonstrate it
- Don’t access user data beyond what’s necessary for proof-of-concept
- Don’t degrade service availability or integrity
- Report through the proper channel — email us first, not a public forum
We consider research conducted under these guidelines to be authorized testing. We will not pursue claims under the Computer Fraud and Abuse Act (CFAA), state computer crime laws, or other legal theories against researchers who follow this policy in good faith.
If you’re unsure whether something is in scope, email us first. We’d rather hear from you and clarify than miss a real vulnerability.
Responsible Disclosure
We ask that you:
- Give us reasonable time to investigate and patch before public disclosure
- Don’t exploit the vulnerability beyond what’s necessary to demonstrate it
- Don’t access user data beyond what’s necessary for proof-of-concept
- Act in good faith — we’re building tools to protect people, not exploit them
We do not pursue legal action against security researchers who follow these guidelines and act in good faith.
Bug Bounty Program
Coming soon. We’re building a formal bounty program with rewards scaled to severity. In the meantime, researchers who report valid, previously unknown vulnerabilities will be acknowledged publicly (if desired) on our Git repository and on this page.
Incident Response
| Phase | Commitment |
|---|---|
| Acknowledgment | Within 48 hours of report |
| Initial assessment | Within 5 business days |
| Critical fixes | Patch within 7 days of confirmation |
| High severity | Patch within 30 days |
| Medium/Low | Patch in next scheduled release |
| Public disclosure | Coordinated with researcher after fix is deployed |
For critical vulnerabilities affecting user funds or data, we will notify affected users directly and publish a post-mortem within 30 days of resolution.
Security by Design
Our security philosophy:
| Principle | Implementation |
|---|---|
| Open source | Every line of code is public. Community review finds bugs before attackers do. |
| Encryption at rest | AES-256-GCM for sensitive data. Argon2id for key derivation. |
| Transport security | TLS 1.3 for all services. HSTS enforced. |
| Minimal data collection | We don’t track users, store PII, or sell data. Less data = less attack surface. |
| Secrets management | All credentials in gopass. Nothing in git. Nothing in .env. |
| Pre-commit guards | Gitleaks, semgrep, bandit, and AI hallucination checkers run on every commit. |
| CI/CD gates | Lint, typecheck, test, audit, and security scans before any deploy. |
| Self-hostable | Run every product on your own hardware. Audit the code. Verify the build. |
| No custody | We never custody user funds or private keys. |
security.txt
Contact: mailto:security@cryptorugmunch.com
Expires: 2027-09-06T00:00:00.000Z
Preferred-Languages: en
Canonical: https://cryptorugmunch.com/.well-known/security.txt
Policy: https://cryptorugmunch.com/security
Automated scanners can also find our security policy at
/.well-known/security.txt.
Acknowledgments
We gratefully acknowledge the security researchers who have helped improve our products:
No reports yet. You could be the first.
Responsible AI
Our AI infrastructure (local llama.cpp, OpenRouter, DeepSeek, Gemini, and others) is used for development automation, code review, and security scanning. We do not train models on user personal data. AI agents operate under strict guardrails (see our AGENTS.md).
Scan data submitted to our hosted products may be used to improve our scam detection models for community benefit — see our Privacy Policy §3 for details.
Report vulnerabilities: security@cryptorugmunch.com