Legal

Security & disclosure

Last updated 2026-09-20 · tapeperp.com

Tape is a read-only analytics terminal. This page is the vulnerability-disclosure policy referenced by /.well-known/security.txt (RFC 9116). Report security issues to security@tapeperp.com — not on public socials, and not as a paid x402 call.

1. What Tape holds — and what it never holds

2. How to report

Email security@tapeperp.com with: the affected URL or endpoint, a short reproduction, impact, and (if you have one) a transaction hash. We acknowledge reports we can act on, usually within a few business days. Do not include customer tokens, API keys, or unrelated personal data.

3. Scope

4. What we already lock down

5. Safe harbor

Good-faith research that stays in scope, avoids privacy harm, and reports to security@tapeperp.com will not be treated as an attack. We do not run a paid bug bounty today; we will credit researchers who want to be named.

Questions that are not security reports: support@tapeperp.com.

Tape is analytics-only and non-custodial. Nothing here is financial advice. Report vulnerabilities to security@tapeperp.com.