Trust CenterReport a vulnerability, responsibly

Bug Bounty

We welcome good-faith security research. If you find a vulnerability, tell us before disclosing it publicly.

Last updated · 22 July 2026

Scope

The OnyxOne web platform, its APIs, and smart contracts once deployed. Denial-of-service, social engineering and physical attacks are out of scope.

How to report

Email a clear, reproducible report to hello@onyxone.co. Give us reasonable time to remediate before any public disclosure. We do not pursue legal action against good-faith researchers who follow this policy.

Rewards

A formal reward tier launches with the platform. Until then we recognise valid reports and will honour them when the program goes live.