Cessio moves real assets on Canton Network. If you find a vulnerability, we want to hear about it before anyone else does.
Email support@cessio.cc with [SECURITY] in the subject.
Please include what you found, how to reproduce it, and what an attacker could do with it. If a proof of concept touches live funds, describe it rather than running it — we can reproduce it on an isolated party.
Do not open a public issue for a security report.
We aim to acknowledge within 3 business days and to keep you updated while we work on a fix. We will credit you in the fix announcement unless you prefer otherwise.
This policy covers every repository in this organization and the live deployment at
devnet.cessio.cc, docs.devnet.cessio.cc and cessio.cc.
Out of scope: the Canton Network protocol and DevNet infrastructure we do not operate, denial-of-service testing against the live deployment, and findings that require a compromised device or browser extension.
Cessio is running on Canton DevNet. Assets are real, but the deployment is pre-production and has not been externally audited. Treat it accordingly.