Responsible disclosure

Report a security issue

Maintained by the Aivessa team.

Scope

Report vulnerabilities affecting Aivessa services, APIs, and dashboards. Do not test third-party services or perform actions that would harm other users.

How to report

  • Email security@aivessa.ai.
  • Include a description, reproduction steps, and impact.
  • Give us reasonable time to investigate and remediate before disclosure.

Our commitment

  • We acknowledge reports within 5 business days.
  • We keep you informed as we investigate.
  • We credit reporters at their request when appropriate.

Out of scope

  • Denial-of-service testing.
  • Social engineering of Aivessa staff or design partners.
  • Physical or network attacks against cloud providers.