Satelink

Responsible Disclosure

Version 2.0 · Last updated September 23, 2026

Draft pending legal review. This policy reflects how Satelink operates today and is written to the applicable Indian and international data-protection standards; it is not yet approved by counsel.

In plain English

  • We welcome good-faith security reports.
  • Email satelinknetwork@gmail.com with clear reproduction steps and give us reasonable time to fix before disclosure.
  • Don't access others' data, degrade service, or exfiltrate data.
  • The website and public API are in scope; third-party services follow their own programs.

We welcome reports of security vulnerabilities and will work in good faith with researchers who follow this policy. This policy explains how to report, what is in and out of scope, the rules of engagement, and the safe-harbour protection we offer to good-faith researchers.

1.How to report

Email satelinknetwork@gmail.com with a clear description, the affected endpoint or page, the impact, and step-by-step instructions to reproduce. Include any proof-of-concept in a form that does not itself cause harm. If your report contains sensitive details, say so and we will arrange a secure channel.

Please give us reasonable time to investigate and remediate before any public disclosure. We will keep you updated as we work through the issue, and we welcome a suggested remediation if you have one. There is no need to include real user data in your report; a minimal, self-contained proof-of-concept against your own account is ideal and helps us reproduce the issue quickly.

2.Rules of engagement

  • Only test against your own account, keys, and data — never another user's.
  • Do not access, modify, or destroy data that is not yours.
  • Do not degrade service for others (no denial-of-service, no load testing against production).
  • Do not exfiltrate data; the minimum needed to demonstrate an issue is enough.
  • Stop as soon as you have confirmed a vulnerability, and report it.

3.Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your testing authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue quickly. This authorization does not extend to violating the privacy of others, disrupting our systems, or destroying data.

4.In scope

The Satelink website (satelink.network) and the public API endpoints under rpc.satelink.network are in scope. Vulnerabilities that could expose user data, allow account or key compromise, bypass metering or spend controls, or lead to unauthorized on-chain actions are of particular interest.

5.Out of scope

  • Third-party services we integrate with (payment processor, hosting providers, blockchain networks) — report those to their own programs.
  • Reports from automated scanners without a demonstrated, exploitable impact.
  • Best-practice suggestions without a concrete vulnerability (e.g. missing headers with no exploit).
  • Social engineering, physical attacks, and denial-of-service.

6.Coordinated disclosure

We practice coordinated disclosure: we ask that you keep the details private until we have released a fix or a reasonable time has passed. We are happy to credit researchers who report valid issues, if you would like recognition.

7.What to expect

We aim to acknowledge reports promptly, triage them by severity and impact, and keep you informed through remediation. Complex issues can take time to fix correctly; we would rather ship a complete fix than a rushed one, and we will explain our reasoning if a fix will take a while.

8.Recognition

We are happy to credit researchers who report valid, previously unknown issues, if you would like public acknowledgement. Let us know how you would like to be named. We currently do not operate a paid bug-bounty program, and a report does not create an entitlement to payment.

9.Legal

This policy is not a waiver of any rights and does not authorize activity that would violate applicable law or the rights of third parties. It is offered in good faith to enable responsible security research on systems we operate. If you are unsure whether a specific test is permitted, ask us first before proceeding.

Version history

  • v2.0 · September 23, 2026Added good-faith safe-harbour language and expectations.
  • v1.0 · September 23, 2026Initial disclosure policy.