Vulnerability Disclosure Policy
At Ravelace, we are committed to maintaining the security and integrity of our systems and data. We encourage security researchers and ethical hackers to report any vulnerabilities they discover in our systems. This policy outlines how to responsibly disclose vulnerabilities and the guidelines for doing so.
This policy applies to all systems, applications, and services owned or operated by Ravelace. It includes, but is not limited to, our websites, APIs, and mobile applications.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability, please report it to us by following these steps:
- Contact Information: https://ravelace.com/contact/
-
Details to Include:
- A description of the vulnerability, including steps to reproduce it.
- The impact of the vulnerability and any potential risks.
- Any relevant screenshots or proof of concept.
- Confidentiality: Please do not disclose the vulnerability publicly until we have had a chance to address it.
Guidelines for Reporting
- Do Not Exploit: Do not exploit the vulnerability or access any data that is not yours.
- No Denial of Service: Avoid any actions that could disrupt our services or systems.
- Respect Privacy: Do not attempt to access or modify data belonging to other users or systems.
- Legal Compliance: Ensure that your testing complies with all applicable laws and regulations.
Response Process
Upon receiving your report, we will:
- Acknowledge receipt of your report within 2 business days.
- Investigate the reported vulnerability and assess its impact.
- Communicate with you regarding the status of your report and any necessary follow-up.
Recognition
We appreciate the contributions of security researchers and may offer recognition for valid reports. If you would like to be recognized, please indicate this in your report.
Policy Updates
This policy may be updated periodically. The latest version will always be available on our website.
