Trust/Responsible disclosure

Found something?
We want to know.

SecurityVault runs a coordinated disclosure program. Acknowledged within 24 hours. No legal action against good-faith research. Bounties paid in USD.

Scope

What is in.
What is out.

Test only against assets you control. Do not touch other tenants. Do not exfiltrate data.

In scope

  • app.securityvault.io and *.securityvault.io subdomains
  • api.securityvault.io and the public API surface
  • The control plane, scan band and audit ledger
  • Authentication, SSO, SCIM provisioning
  • Customer tenant isolation
  • Open-source components on github.com/securityvault

Out of scope

  • Social engineering of staff or customers
  • Physical attacks against offices
  • Denial of service or rate-limit testing
  • Spam on marketing pages
  • Vulnerabilities in third-party services
  • Issues already published or under embargo
Rewards

Bounty schedule.

Bounties paid via HackerOne or direct wire. Anonymous reports honored.

SeverityAcknowledgmentTriageReward · USD
Critical
RCE, auth bypass, evidence forgery
< 24h< 72hup to $30,000
High
Privilege escalation, tenant boundary
< 48h< 7dup to $10,000
Medium
SSRF, IDOR, business-logic
< 5d< 30dup to $3,000
Low
Information leak, hardening
< 14dbest effortswag · CVE credit
Early access

Bring a repo and a cluster.
Watch the graph connect.

A 30-minute call with a SecurityVault security engineer — your environment, your fleet, a hash-verifiable evidence demo.