Skip to content

Vulnerability disclosure

Report a security issue to [email protected], test only your own company, and give Avaloi time to fix it.

Report vulnerabilities to [email protected]. Avaloi reads that inbox. A security.txt file on avaloi.com points there.

How to report

  • Email a clear description, the steps, and the impact.
  • Use your own test account and company. Do not touch other tenants.
  • Do not access or exfiltrate customer data.
  • Give Avaloi a reasonable window before you publish.

Avaloi acknowledges the report and tells you when a fix ships. Avaloi prefers coordinated disclosure.

Out of scope (draft)

  • Social engineering of staff or customers.
  • Denial of service against production.
  • Reports that only say a library has a CVE, with no Avaloi impact.
  • Missing best-practice headers without a working issue.

Avaloi does not pay a bounty under this draft. That may change after launch.

Quick answers

Can I test against a free test site? Yes, in your own company. A test site runs on a simulated server and costs nothing.

I think my account was taken over. Email [email protected]. Support will not argue with an attacker who already holds one factor, and account recovery needs two of three proofs.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.