E-VARA takes security seriously. We value the work of security researchers and are committed to a responsible disclosure process.
If you believe you have found a security vulnerability in E-VARA, please report it to us as soon as possible.
- Reporting: Email evara.securityai@gmail.com (placeholder) or open a private security advisory on GitHub.
- Confidentiality: Do not disclose the vulnerability publicly until we have had a reasonable amount of time to address it.
- Scope: Vulnerabilities in the core application, infrastructure, or data processing logic.
- We will acknowledge your report within 48 hours.
- We will provide a transparent timeline for remediation.
- We will credit you in our security hall of fame (if applicable) for valid, responsibly disclosed findings.
- Denial of Service (DoS) attacks.
- Social engineering against users or staff.
- Accessing or modifying data that does not belong to you.
Protecting the protectors.