// SECURITY

Responsible Disclosure

DRAFT — requires human legal review before relying on this text in procurement.

Last updated: 26 July 2026

Report a vulnerability

Email [email protected] with a description, steps to reproduce, and impact assessment. Encrypt sensitive details if needed (PGP on request).

Safe harbour

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before public disclosure.

Response timeline

We aim to acknowledge reports within 3 business days and provide a substantive update within 15 business days.

Out of scope

Social engineering, physical attacks, denial-of-service, and issues in third-party services without demonstrable impact on Vex Raptor customers.