Report a vulnerability

If you believe you have found a security vulnerability in Cevoriq, please tell us before you tell anyone else. This page says how, and what you can expect.

How to report

Email support@cevoriq.com with the subject “Security report”. The same contact is published in our security.txt. Describe what you found, the steps to reproduce it, and the impact you believe it has. Please do not include other people's data in your report.

We aim to acknowledge your report within 3 business days. That is a target for the first reply, not a promise about when a fix will ship.

In scope

  • cevoriq.com and its pages and API routes
  • eu.cevoriq.com and its pages and API routes

Out of scope

  • Denial of service, load testing and anything that degrades the service for others
  • Social engineering or phishing of Cevoriq staff, customers or partners
  • Other tenants' data. If you reach data that is not yours, stop, do not copy or keep it, and report what you did to get there
  • Physical attacks, and the infrastructure of our sub-processors

Good-faith research

If you act in good faith, follow this policy, stay within the scope above, avoid privacy harm and disruption, and give us a reasonable chance to fix the issue before you disclose it, we will not pursue legal action against you for your research. This statement covers Cevoriq's own systems only and does not bind third parties.

Rewards

Cevoriq has no bounty programme and pays no reward for reports.