Security & Responsible Disclosure
Last updated 2026-07
We welcome reports of security issues in the Canopy Facilitator or Discovery.
- Report vulnerabilities privately and give us reasonable time to remediate before public disclosure.
- Do not access data that is not yours, degrade the service, or execute destructive tests.
- Contact: security@canopyfinance.io. Facilitator source is currently private and available to partners, auditors, and security researchers on request. Public buyer SDK: github.com/canopyfinance/x402-rwa.
- The facilitator is non-custodial: it relays payer-signed Permit2 authorizations and never holds user funds. Relayer key handling is documented in the technical docs.
- This software has not undergone a third-party security audit. Assess suitability before relying on it for high-value flows.
This document is provided for transparency and is not legal advice. Canopy Discovery provides discovery and payment settlement infrastructure only and does not audit, endorse, or guarantee listed services.