Security and responsible disclosure

Operational transparency document · July 2026

DecentraLabs applies security controls at the browser, API, gateway, institutional-backend and smart-contract boundaries. This page gives users and providers a practical summary.

Current controls

  • Opaque server-side sessions, SAML/WebAuthn integration and authorization checks for sensitive operations.
  • Exact-origin trust for provider metadata and institutional backends, HTTPS requirements in production, DNS and redirect protections for server-side fetches.
  • Sandboxed same-origin document previews, referrer suppression, restrictive Permissions-Policy and nonce-based CSP for application documents.
  • Normalized public API errors with correlation IDs; detailed diagnostics remain in bounded, redacted server logs.

Provider responsibilities

Providers must keep their institutional backend, identity integration, wallet administration and uploaded content secure. Register only origins and keys that the institution controls, rotate compromised credentials, and report changes or incidents promptly.

Reporting a vulnerability

Use the Contact page to report a suspected vulnerability. Do not include passwords, SAML assertions, bearer tokens, private keys or full personal-data exports in the initial report. Include the affected route, approximate time, safe reproduction steps and any returned correlation ID.

Disclosure process

Report suspected vulnerabilities to contact@nebsyst.com without including passwords, SAML assertions, bearer tokens or private keys. The security contact, response targets, supported versions and coordinated-disclosure terms must be confirmed by the project owner before this page is considered a formal security policy.