Responsible Disclosure
How to report security issues and what to expect from our response process.
How to report
Report potential security issues to privacy@vostego.com. Include reproducible steps, impact summary, and affected endpoints or workflows.
<section>
<h2>Response targets</h2>
<ul>
<li>Acknowledgment target: within 3 business days</li>
<li>Triage target: as quickly as practical based on severity and reproducibility</li>
<li>Status updates: provided for materially impactful issues while remediation is in progress</li>
</ul>
</section>
<section>
<h2>Scope and expectations</h2>
<ul>
<li>Do not attempt destructive testing, denial of service, or social engineering.</li>
<li>Do not access data that does not belong to you.</li>
<li>Provide enough detail to let us reproduce and resolve the issue quickly.</li>
</ul>
</section>