Skip to content

Security: chaplinkyle/baton-web

SECURITY.md

Security policy

Baton Web is a non-custodial transaction-building interface for a Preprod-only contract candidate. Do not use this release with Mainnet or valuable assets.

Report a vulnerability

Use GitHub's Report a vulnerability flow to open a private security advisory. Do not publish wallet secrets, signed transactions, personal information, or exploit details in an issue.

Include the application release, contract validator hash, affected route or transaction action, reproduction steps, impact, and test environment. The site never needs a seed phrase or private key; any flow requesting one is not Baton.

The canonical on-chain security policy is maintained in chaplinkyle/baton-cardano.

There aren't any published security advisories