Back to RAVIONIX
Responsible Disclosure
Reporting a vulnerability.
If you have found a security issue in RAVIONIX, we want to hear about it. This page sets out scope, safe harbour and the response you can expect.
Reviewed September 2026
How to report
Send a description of the issue, the affected component and reproduction steps to the security address below. Please give us a reasonable period to remediate before any public disclosure.
What we commit to
- Acknowledgement within 3 business days.
- A triage decision and severity assessment within 10 business days.
- Regular status updates until the issue is resolved.
- Credit in our advisory, if you would like it.
Safe harbour
We will not pursue legal action for good-faith research that respects this policy: no privacy violations, no data destruction, no service degradation, and no access to data beyond the minimum needed to demonstrate the issue.
Out of scope
- Findings from automated scanners without a demonstrated impact.
- Social engineering of RAVIONIX staff or customers.
- Denial-of-service testing against production systems.
- Reports concerning third-party services we integrate with — please report those to the vendor.