# Security & bug bounty \[Audited contracts, and up to $50,000 for critical vulnerabilities]

Splits' contracts are open source in [splits-contracts-monorepo](https://github.com/0xSplits/splits-contracts-monorepo) and independently audited; see the [audit reports](https://github.com/0xSplits/splits-contracts-monorepo/tree/main/audits). After launch, a bug bounty keeps independent researchers reviewing the code.

The bounty's source of truth is [SECURITY.md](https://github.com/0xSplits/splits-contracts-monorepo/blob/main/SECURITY.md); in summary:

* **Scope**: vulnerabilities in the monorepo's deployed production contracts that could lead to loss of user funds.
* **Out of scope**: test and script code, dependencies not used by deployed contracts, testnet deployments, third-party contracts, previously reported issues, and non-contract vectors (frontend bugs, phishing, social engineering, private key compromise).
* **Rewards**: up to **$50,000** for critical fund-loss bugs; lower severities at the team's discretion.
* **Reporting**: email **security@splits.org** within 24 hours of discovery, include reproduction steps or a proof of concept, and keep the issue confidential until it's patched.
* **Safe harbor**: good-faith research that follows the policy is protected.
