Responsible disclosure

Report a vulnerability in Vellaci

We welcome reports from security researchers and customers. We acknowledge within 2 business days, keep you informed, and coordinate publication. Please do not access other customers' data, run denial-of-service tests or use social engineering.

Please avoid including other customers' data. Proof-of-concept details are welcome.

Scope

Vellaci web application, public API, CLI, integrations and infrastructure operated by Vellaci. Third-party services are out of scope unless the issue is in how Vellaci uses them.

What we commit to

  • Acknowledge within 2 business days
  • Triage and severity assessment within 5 business days
  • Fix timelines: critical 7 days, high 30 days, medium 90 days
  • Credit in our acknowledgments (opt-in)
  • No legal action against good-faith research

Encrypted contact

E-mail security@vellaci.ch. A PGP key is provided on request until published here.

Acknowledgments

No public acknowledgments yet.