RESPONSIBLE DISCLOSURE
Help investigate security issues without putting others at risk.
Coordinated disclosure starts with private contact, explicit scope and respect for customer systems, privacy and service availability.
GOOD-FAITH REPORTING
Report potential issues privately.
Use the configured security contact for vulnerabilities affecting assets explicitly controlled by EVIDRYN. Provide enough detail for reproduction without including credentials or customer data.
Contact SecurityTesting boundaries
- Do not test customer systems or data
- No privacy violations, data destruction or denial of service
- No social engineering or credential attacks
- Do not exceed assets explicitly confirmed in scope
- Allow reasonable investigation time and coordinate disclosure
No bug-bounty promise
EVIDRYN does not currently promise payment, safe-harbor terms beyond applicable law or a formal bounty. Good-faith reports will be reviewed through the founder-assisted security process.