Vulnerability disclosure
Report a security issue to [email protected], test only your own company, and give Avaloi time to fix it.
Report vulnerabilities to [email protected]. Avaloi reads that inbox. A security.txt file on avaloi.com points there.
How to report
- Email a clear description, the steps, and the impact.
- Use your own test account and company. Do not touch other tenants.
- Do not access or exfiltrate customer data.
- Give Avaloi a reasonable window before you publish.
Avaloi acknowledges the report and tells you when a fix ships. Avaloi prefers coordinated disclosure.
Out of scope (draft)
- Social engineering of staff or customers.
- Denial of service against production.
- Reports that only say a library has a CVE, with no Avaloi impact.
- Missing best-practice headers without a working issue.
Avaloi does not pay a bounty under this draft. That may change after launch.
Quick answers
Can I test against a free test site? Yes, in your own company. A test site runs on a simulated server and costs nothing.
I think my account was taken over. Email [email protected]. Support will not argue with an attacker who already holds one factor, and account recovery needs two of three proofs.
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.