// SECURITY
Responsible Disclosure
DRAFT — requires human legal review before relying on this text in procurement.
Last updated: 26 July 2026
Report a vulnerability
Email [email protected] with a description, steps to reproduce, and impact assessment. Encrypt sensitive details if needed (PGP on request).
Safe harbour
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before public disclosure.
Response timeline
We aim to acknowledge reports within 3 business days and provide a substantive update within 15 business days.
Out of scope
Social engineering, physical attacks, denial-of-service, and issues in third-party services without demonstrable impact on Vex Raptor customers.