Skip to content

Legal

Security

Last updated: June 17, 2026

Draft for review — not yet a final legal document.

Security is foundational to building on-chain. This page outlines how we approach the security of our products and how to report a vulnerability.

Our approach

We design our products to minimize risk: least-privilege access, encrypted transport, and regular review of our infrastructure and dependencies. Security is considered throughout development, not bolted on at the end.

Smart contracts and audits

Where our products rely on on-chain programs, we aim to keep them transparent and reviewable, and to engage independent audits for high-risk components before broad release. On-chain code carries inherent risk; we work to reduce it, not to eliminate the reality of it.

Non-custodial by default

Our products are designed to be non-custodial wherever possible — you keep control of your keys and assets. We never ask for your seed phrase or private keys, and no member of the Aerosol team will ever do so.

Your responsibilities

Protect your wallet, keys, and recovery phrase. Verify URLs and contract addresses before signing. Be alert to phishing and impersonation — official communication only comes from our verified channels and aerosol.so addresses.

Responsible disclosure

If you discover a vulnerability, please report it privately to security@aerosol.so before disclosing it publicly. Include enough detail to reproduce the issue. We will acknowledge your report, investigate, and keep you informed as we work on a fix. We appreciate and credit responsible researchers.

Contact

Security reports and questions: security@aerosol.so.