Skip to main content
Legal

Responsible Disclosure

Last updated: 2026-04-26

·

Security disclosures: security@avyonintelligence.com · Encrypted reports welcome

How security researchers can report issues and how Avyon Intelligence responds to validated findings.

Our disclosure policy

Avyon welcomes responsible disclosure of security vulnerabilities. We are committed to working with security researchers who discover and report vulnerabilities in good faith, and to acknowledging valid findings in a timely manner. We do not pursue legal action against researchers who comply with this policy.

What to report

We welcome reports of: authentication and authorisation vulnerabilities in Avyon-operated systems, injection vulnerabilities (SQL, command, template), sensitive data exposure, cross-site scripting (XSS), cross-site request forgery (CSRF), security misconfigurations in Avyon infrastructure, and cryptographic weaknesses. We are not interested in: volumetric denial-of-service attacks, social engineering of Avyon staff, physical security issues, or vulnerabilities in third-party systems not under Avyon's control.

How to report

Report vulnerabilities to security@avyonintelligence.com. Encrypt sensitive reports using our PGP key (available on request). Include: a description of the vulnerability, steps to reproduce, potential impact assessment, and your contact details. We will acknowledge receipt within 2 business days.

Our response commitment

We will: acknowledge your report within 2 business days, provide a triage assessment within 10 business days, keep you informed of progress toward resolution, notify you when the vulnerability is resolved, and acknowledge your contribution in our security hall of fame (unless you prefer to remain anonymous).

Safe harbour

If you make a good-faith effort to comply with this policy, we will not recommend legal action against you. We consider security research conducted in accordance with this policy to be authorised access. We ask that you: not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability, not perform testing on systems you do not have authorisation to test, not disclose vulnerabilities publicly before we have had a reasonable opportunity to resolve them (90 days from triage), and not use vulnerabilities for any purpose beyond confirming their existence.