← Return to home

Responsible Disclosure Policy

Last Updated: July 8, 2026

1. Commitment to Security

At Verallax, security is the foundation of our platform. We appreciate the role of independent security researchers in keeping our services safe. This Responsible Disclosure Policy outlines our guidelines for discovering and reporting potential security vulnerabilities.

2. Reporting Guidelines

If you identify a vulnerability in our application, API, Nginx proxies, or cloud environments, we ask that you:

  • Email your findings directly to [email protected].
  • Provide detailed technical steps, proof-of-concept logs, or request/response payloads to reproduce the issue.
  • Avoid performing destructive actions (e.g. SQL injection that deletes tenant data, volumetric Denial of Service, or cross-tenant credential brute-forcing).
  • Give us a reasonable timeframe (minimum 30 days) to mitigate the issue before public disclosure.

3. Excluded Activities

The following activities are strictly prohibited under this policy:

  • Social engineering or phishing of Verallax employees or customers.
  • Resource exhaustion attacks (DDoS) against our edge load balancers or Cloudflare Turnstile verification gates.
  • Exposing, leaking, or copying customer AWS Role ARNs or metadata.

4. Safe Harbor

We will not pursue legal action or suspend your account for security research that strictly adheres to the guidelines of this disclosure policy. Thank you for your contribution to the cloud security community!