Skip to content
avertaritrust
Report a vulnerability ← avertari.io Request the security pack

Security

Vulnerability disclosure policy

Effective 24 September 2026

On this page

  1. How to report
  2. Scope
  3. What we ask
  4. What we commit to
Draft. This document is being reviewed by our legal advisers and may change before general availability. Questions: legal@avertari.io.

How to report

If you think you've found a security vulnerability in Avertari - the app at app.avertari.io, our websites, or our infrastructure - email security@avertari.io with enough detail for us to reproduce it. Our security.txt follows RFC 9116.

Scope

  • In scope: *.avertari.io and the Avertari application.
  • Out of scope: denial of service, social engineering, physical attacks, spam or rate-limit findings without a security impact, and reports from automated scanners without a demonstrated issue.

What we ask

  • Give us reasonable time to fix the issue before disclosing it publicly. We aim for 90 days and will agree a date with you.
  • Only test against accounts and data you own. Don't access, change or keep other people's data - if you reach any, stop and tell us.
  • Don't degrade the service for other users.

What we commit to

  • We'll acknowledge your report within 3 business days and keep you updated until it's resolved.
  • We won't pursue legal action over research that follows this policy in good faith.
  • With your permission, we'll credit you once the issue is fixed.

© 2026 Avertari. avertari.io · Privacy · security@avertari.io

No tracking cookies. The request form uses Cloudflare Turnstile to keep bots out.