Report a security issue.
Found a security issue in Verillian? Tell us before you go public. Every report gets read by the people who can fix it. You'll hear back quickly, and we'll keep you posted all the way through the fix.
How to report
Email [email protected]. If the details are sensitive, just ask us for an encryption key first and we'll send you one. We'll acknowledge your report promptly and keep you in the loop until it's resolved.
What to include
Send us a clear description of the issue, the steps to reproduce it, the affected versions or endpoints, and any proof of concept you have. The more of it we can reproduce on our side, the faster we can fix it.
What we ask
Give us reasonable time to investigate and fix the issue before you disclose it publicly, and please don't access, modify, or copy any data that isn't yours.
What you can expect
You can expect an acknowledgment, an assessment, a timeline for the fix, and credit if you'd like it. And if you're reporting in good faith, we won't pursue legal action against you.
security.txt
If you'd rather pull our contact details automatically, they're published in machine-readable form at /.well-known/security.txt.
Here for a security review instead?
The trust center holds the frameworks, the plainly stated limits, and the paperwork. If you'd rather just ask, email us and we'll answer.