Security

ACODA operates a read-only market-intelligence API and welcomes responsible security reports.

Report a vulnerability

Email sean@acoda.xyz with a clear description, affected URL, reproduction steps, and potential impact. Do not include secrets or personal information you do not own.

Responsible testing

Avoid privacy violations, service disruption, destructive testing, social engineering, denial-of-service activity, and access to data beyond what is necessary to demonstrate the issue.

Safe harbor

We will make a good-faith effort to review legitimate reports and coordinate remediation. This page does not authorize activity that violates law or third-party rights.

Service design

The public API is read-only. Secrets are supplied through protected deployment configuration and are not embedded in public source or client pages.

Machine-readable disclosure information is available at /.well-known/security.txt.