Responsible Disclosure & Security
Entity U.CASH Inc.
Version 2026-08-06
Effective Aug 6, 2026
We welcome reports of security vulnerabilities from researchers and users. This page explains our safe-harbor commitments, what is in scope, and how to report.
Safe harbor
If you make a good-faith report of a vulnerability in accordance with this policy, we will not pursue legal action against you for that research. We ask in return that you:
- avoid accessing, modifying, or deleting other people's data;
- do not degrade, disrupt, or deny service to U.CASH or its users (no denial-of-service, spam, or brute force);
- do not exploit the issue beyond the minimum needed to demonstrate it;
- give us reasonable time to investigate and remediate before disclosing the issue publicly.
In scope
- u.cash and all *.u.cash applications and APIs we operate (pay, swap, buy, names, agents, verify, send, portal, ai, una, status).
- Authentication, session handling, authorization, and access controls.
- Server-side input handling, payment-link and checkout logic, and webhook integrity.
- The U.CASH SDKs and developer tooling.
Out of scope
- Vulnerabilities in third-party smart contracts, decentralized exchanges, liquidity sources, bridges, domain registries, or payment processors. Report those to their owners.
- Public blockchains and on-chain contracts U.CASH does not deploy.
- Social engineering, physical attacks, and attacks requiring an insider.
- Findings from automated scanners without a demonstrated, specific impact.
How to report
Email [email protected] with a clear description and steps to reproduce. If possible, encrypt sensitive details. We acknowledge reports within 48 hours and aim to keep reporters informed through to resolution. Please do not report security issues through public channels.
Rewards and recognition
We may recognize contributors and, for significant reports, provide rewards at our discretion based on impact.
Security posture
U.CASH is non-custodial: we do not hold user funds, private keys, or seed phrases, which removes a major class of risk. We use encryption in transit and at rest, least-privilege access controls, isolation between tenants, signed webhooks, and screening against sanctions lists. Live availability is published at status.u.cash. See our Privacy Policy for how we handle personal information.