RESPONSIBLE DISCLOSURE

Help investigate security issues without putting others at risk.

Coordinated disclosure starts with private contact, explicit scope and respect for customer systems, privacy and service availability.

GOOD-FAITH REPORTING

Report potential issues privately.

Use the configured security contact for vulnerabilities affecting assets explicitly controlled by EVIDRYN. Provide enough detail for reproduction without including credentials or customer data.

Contact Security

Testing boundaries

  • Do not test customer systems or data
  • No privacy violations, data destruction or denial of service
  • No social engineering or credential attacks
  • Do not exceed assets explicitly confirmed in scope
  • Allow reasonable investigation time and coordinate disclosure

No bug-bounty promise

EVIDRYN does not currently promise payment, safe-harbor terms beyond applicable law or a formal bounty. Good-faith reports will be reviewed through the founder-assisted security process.