Responsible disclosure
Report a vulnerability in Vellaci
We welcome reports from security researchers and customers. We acknowledge within 2 business days, keep you informed, and coordinate publication. Please do not access other customers' data, run denial-of-service tests or use social engineering.
Scope
Vellaci web application, public API, CLI, integrations and infrastructure operated by Vellaci. Third-party services are out of scope unless the issue is in how Vellaci uses them.
What we commit to
- Acknowledge within 2 business days
- Triage and severity assessment within 5 business days
- Fix timelines: critical 7 days, high 30 days, medium 90 days
- Credit in our acknowledgments (opt-in)
- No legal action against good-faith research
Encrypted contact
E-mail security@vellaci.ch. A PGP key is provided on request until published here.
Acknowledgments
No public acknowledgments yet.