Skip to content

RESPONSIBLE DISCLOSURE

Found something? Tell us before you tell the internet.

If you believe you've found a vulnerability in Scvltori, email security@scvltori.com. Please don't open a public issue.

What to include

  • What the vulnerability is, and why it's a risk.
  • Steps to reproduce it.
  • What data or systems it could affect.
  • A proof of concept, if you have one.
  • Your severity estimate — CVSS v3.1 if you use it.

What to expect

We aim to acknowledge your report within two business days and give you a tracking ID. From there we'll come back with our severity assessment and what we plan to do about it, usually within a week.

Critical and high severity findings take priority and we work to ship those fixes first; lower severity ones are queued into a normal release. If something is going to take longer than we thought, we'll tell you rather than go quiet.

How we handle it

We follow coordinated disclosure: we'll work with you to understand and fix the issue before anything is published, and we'll credit you in the advisory if you want the credit.

We will not pursue legal action against researchers acting in good faith.

Testing against our environment

Scvltori is multi-tenant: our hosted environment is shared infrastructure that other customers depend on. Automated scanning, fuzzing, brute force, and load or denial-of-service testing against it are not permitted — not as a legal formality, but because they degrade service for people who never agreed to be part of your test, and they bury real attacks in noise.

Work within your own workspace and your own data. If a finding needs more than that to demonstrate, write to us first and we'll agree on a safe way to reproduce it.

Findings that come out of normal use of the product are always welcome, and the good-faith protection above applies to them.

Scope

The Scvltori platform and this website. If you found it in something we run, we want to hear about it.

Out of scope

  • Scanner output with no demonstrated impact.
  • Vulnerabilities already public in third-party dependencies — report those upstream.
  • Social engineering or phishing against our team or our customers.
  • Anything that requires physical access to a server.