If you discover a security issue in the Demos Network Oracle — whether in the code at this repository, in the live service at demos-oracle.com, or in the data it publishes — please report it privately before disclosing publicly.
Contact: cypherx22@protonmail.com
Please include:
- A description of the issue
- Steps to reproduce (if applicable)
- The potential impact
- Your contact information (optional)
In scope:
- The Oracle service at demos-oracle.com and its API endpoints
- The source code in this repository
- Data integrity issues in
/organismoutput or any other published endpoint - Authentication / authorization issues on admin endpoints
Out of scope:
- The Demos blockchain itself (report to the Demos team)
- SuperColony infrastructure (report to SuperColony)
- Third-party services the Oracle observes (e.g., individual validator nodes)
- Issues in deprecated endpoints that are no longer publicly reachable
- Acknowledgment of your report within a reasonable time frame
- Coordinated disclosure if the issue warrants it
- Credit in any public disclosure (if you want it)
This is an independent, unfunded community service. There is no bug bounty program. Reports are appreciated and will be handled with care, but no monetary reward is offered.