Legal
Security
Last updated: June 17, 2026
Draft for review — not yet a final legal document.
Security is foundational to building on-chain. This page outlines how we approach the security of our products and how to report a vulnerability.
Our approach
We design our products to minimize risk: least-privilege access, encrypted transport, and regular review of our infrastructure and dependencies. Security is considered throughout development, not bolted on at the end.
Smart contracts and audits
Where our products rely on on-chain programs, we aim to keep them transparent and reviewable, and to engage independent audits for high-risk components before broad release. On-chain code carries inherent risk; we work to reduce it, not to eliminate the reality of it.
Non-custodial by default
Our products are designed to be non-custodial wherever possible — you keep control of your keys and assets. We never ask for your seed phrase or private keys, and no member of the Aerosol team will ever do so.
Your responsibilities
Protect your wallet, keys, and recovery phrase. Verify URLs and contract addresses before signing. Be alert to phishing and impersonation — official communication only comes from our verified channels and aerosol.so addresses.
Responsible disclosure
If you discover a vulnerability, please report it privately to security@aerosol.so before disclosing it publicly. Include enough detail to reproduce the issue. We will acknowledge your report, investigate, and keep you informed as we work on a fix. We appreciate and credit responsible researchers.
Contact
Security reports and questions: security@aerosol.so.