Responsible disclosure: report security issues privately

Report a suspected vulnerability privately to support@vaultpilot.io, as a separate security report. Never post exploit details, secrets, customer data, credentials, tokens, certificates, databases, or backups anywhere public.

Channel
Private security reporting
Detail
Minimal and redacted
Public posts
No exploit or secret material
A private route carrying a redacted security report into a protected review channel

Security report or support request

Both go to support@vaultpilot.io, but a security report goes as its own private message, never inside a support thread.

  • Support: a product defect, a documentation question, or an operational failure
  • Security report: a weakness that could affect confidentiality, integrity, authorization, update trust, or another security boundary

Start with the smallest reproduction

Do not open with full logs, a database, a backup, a certificate package, a customer screenshot, or a working exploit. The first report needs only the following.

  • Affected version and component
  • Kind of environment and preconditions
  • A short sequence of steps, with expected and observed results
  • Redacted timestamps and error names

Send more only when asked

If the investigation needs material that cannot be made safe to share, wait for the approved private handling instructions and send only what is requested. Keep the originals secure. Do not test against systems or data you are not authorized to touch.

Limits to know

Check step by step

  1. 01

    Confirm the report concerns a security boundary and not ordinary support.

  2. 02

    Note the exact version, area, preconditions, and observed impact.

  3. 03

    Remove secrets and customer identifiers from the first report.

Read more in the guides: Security and trust model, Support evidence pack