Security

Reporting a vulnerability

If you have found a security issue in Vallorix or on this site, we want to hear from you.

How to reach us

Email security@vallorix.ai · Report a vulnerability. Include enough detail to reproduce the issue — affected URL or component, the steps you took, and what you observed. If a report contains sensitive material, say so and we will arrange a secure channel before you send it.

This address is also published at /.well-known/security.txt in the format described by RFC 9116, so automated tooling can find it.

What we ask

Self-hosted deployments

Vallorix runs on your infrastructure. A vulnerability in the software itself is ours to fix and we want the report; the configuration, hosting and access control of a particular deployment belong to whoever runs it. If you are reporting something you found in your own environment, tell us which version you are on so we can tell the two apart.

Scope

The Vallorix application, this website, and app.vallorix.ai. We do not currently operate a paid bug-bounty programme, and we will not pursue action against good-faith research that follows the guidance above.

V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect