> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dionysus.finance/llms.txt
> Use this file to discover all available pages before exploring further.

# Responsible disclosure

> How to tell us something is broken.

If you believe you've found a security vulnerability in Dionysus — contracts, app, API, or infrastructure — please report it privately before any public disclosure.

## How to report

Email **[security@dionysus.finance](mailto:security@dionysus.finance)** with:

* A description of the issue and its impact as you understand it
* Steps to reproduce (a fork-based PoC is ideal)
* Your contact for follow-up, and an address if you wish to be eligible for a reward

You will receive an acknowledgement within 48 hours.

## What we ask

* **Do not test against live vaults.** Every vault is one person's private capital.
* **Do not exploit, front-run, or extract value**, even provably-returnable value, even as a demonstration.
* Give us reasonable time to remediate before publishing. We commit to moving fast and to crediting you (or preserving your anonymity — your choice) in any disclosure.

## What you can expect

Good-faith reports get good faith back: no legal threats for research conducted within these rules, honest severity assessment, and reward consideration under the [bug bounty](/reference/security/bug-bounty) terms — including before the formal program launches.
