We take the security of our applications seriously.

Rug Munch Media builds open-source software that protects retail crypto investors. The security of that software is fundamental to our mission. We develop in the open because we believe transparent code, reviewed by the community, is more secure than closed-source alternatives.

If you discover a security vulnerability in any Rug Munch Media product or infrastructure, we want to hear from you.


Report a Vulnerability

Email: security@cryptorugmunch.com

PGP Key: Available on request.

Please include:

  • A detailed description of the vulnerability
  • Steps to reproduce the issue
  • Affected product(s) and version(s)
  • Your assessment of severity
  • Any suggested remediation (if known)

We will acknowledge your report within 48 hours and provide a timeline for resolution within 5 business days.


Scope

In Scope

  • All websites operated by Rug Munch Media LLC (cryptorugmunch.com, rugmunch.io, pryscraper.com, degenfeed.xyz, walletpress.cc)
  • Our self-hosted Forgejo instance (git.rugmunch.io)
  • Our MCP servers and API endpoints
  • The RugMunchBot Telegram bot
  • Infrastructure directly operated by us (DNS, CDN configuration, mail server)

Out of Scope

  • Vulnerabilities in third-party services we don’t operate (blockchain networks, Telegram, Cloudflare) — report to the respective provider
  • Vulnerabilities requiring physical access to our servers
  • Social engineering of our team members
  • Denial of service via volumetric attacks (we have Cloudflare DDoS protection)
  • Findings from automated tools without manual verification
  • Bugs in open-source dependencies — report upstream, and we’ll patch on our end

Safe Harbor

We will not initiate or support legal action against security researchers who:

  1. Act in good faith — you’re testing to improve security, not to exploit users
  2. Give us reasonable time to investigate and patch before public disclosure (90 days minimum)
  3. Don’t exploit the vulnerability beyond what’s necessary to demonstrate it
  4. Don’t access user data beyond what’s necessary for proof-of-concept
  5. Don’t degrade service availability or integrity
  6. Report through the proper channel — email us first, not a public forum

We consider research conducted under these guidelines to be authorized testing. We will not pursue claims under the Computer Fraud and Abuse Act (CFAA), state computer crime laws, or other legal theories against researchers who follow this policy in good faith.

If you’re unsure whether something is in scope, email us first. We’d rather hear from you and clarify than miss a real vulnerability.


Responsible Disclosure

We ask that you:

  1. Give us reasonable time to investigate and patch before public disclosure
  2. Don’t exploit the vulnerability beyond what’s necessary to demonstrate it
  3. Don’t access user data beyond what’s necessary for proof-of-concept
  4. Act in good faith — we’re building tools to protect people, not exploit them

We do not pursue legal action against security researchers who follow these guidelines and act in good faith.


Bug Bounty Program

Coming soon. We’re building a formal bounty program with rewards scaled to severity. In the meantime, researchers who report valid, previously unknown vulnerabilities will be acknowledged publicly (if desired) on our Git repository and on this page.


Incident Response

Phase Commitment
Acknowledgment Within 48 hours of report
Initial assessment Within 5 business days
Critical fixes Patch within 7 days of confirmation
High severity Patch within 30 days
Medium/Low Patch in next scheduled release
Public disclosure Coordinated with researcher after fix is deployed

For critical vulnerabilities affecting user funds or data, we will notify affected users directly and publish a post-mortem within 30 days of resolution.


Security by Design

Our security philosophy:

Principle Implementation
Open source Every line of code is public. Community review finds bugs before attackers do.
Encryption at rest AES-256-GCM for sensitive data. Argon2id for key derivation.
Transport security TLS 1.3 for all services. HSTS enforced.
Minimal data collection We don’t track users, store PII, or sell data. Less data = less attack surface.
Secrets management All credentials in gopass. Nothing in git. Nothing in .env.
Pre-commit guards Gitleaks, semgrep, bandit, and AI hallucination checkers run on every commit.
CI/CD gates Lint, typecheck, test, audit, and security scans before any deploy.
Self-hostable Run every product on your own hardware. Audit the code. Verify the build.
No custody We never custody user funds or private keys.

security.txt

Contact: mailto:security@cryptorugmunch.com
Expires: 2027-09-06T00:00:00.000Z
Preferred-Languages: en
Canonical: https://cryptorugmunch.com/.well-known/security.txt
Policy: https://cryptorugmunch.com/security

Automated scanners can also find our security policy at /.well-known/security.txt.


Acknowledgments

We gratefully acknowledge the security researchers who have helped improve our products:

No reports yet. You could be the first.


Responsible AI

Our AI infrastructure (local llama.cpp, OpenRouter, DeepSeek, Gemini, and others) is used for development automation, code review, and security scanning. We do not train models on user personal data. AI agents operate under strict guardrails (see our AGENTS.md).

Scan data submitted to our hosted products may be used to improve our scam detection models for community benefit — see our Privacy Policy §3 for details.


Report vulnerabilities: security@cryptorugmunch.com