Our security commitment
We implement technical, administrative and physical safeguards appropriate to the sensitivity of the information we handle — including encryption in transit, access controls, monitoring, and regular review of our practices. No system is perfectly secure, but we work continuously to protect the Services and to respond quickly to issues.
Reporting a vulnerability
If you believe you have found a security vulnerability, please report it to us privately at compliance@edverise.com with enough detail to reproduce the issue. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.
Guidelines for researchers (safe harbour)
We will not pursue or support legal action against researchers who, in good faith:
Report promptly and give us reasonable time to fix the issue before disclosure;
Avoid privacy violations, data destruction, service disruption or degradation of user experience;
Access only the minimum data necessary to demonstrate the issue and do not store, share or exploit it; and
Do not use social engineering, physical attacks, spam, or attacks against our staff or infrastructure beyond the tested vulnerability.
Out of scope
Activities such as denial-of-service, automated scanning that degrades the Services, testing third-party services we do not control, and reports without a demonstrable security impact are generally out of scope. We assess reports case by case.
Our response
We aim to acknowledge valid reports promptly, keep you informed of progress, and remediate confirmed issues in a timely manner. Where appropriate, we are happy to credit researchers who report responsibly.
Contact: compliance@edverise.com
Questions about this policy?
Our compliance team and Grievance Officer respond to every request.