- In scope
- aevral.com, app.aevral.com, the Aevral GitHub App and the Aevral worker that runs scans and pull request reviews.
- Out of scope
- Other Better ISMS products and sites, third-party services we use (report those to their owners), denial of service, spam, social engineering and physical attacks.
- What to include
- The affected URL, repository setup or request; steps to reproduce; what an attacker could do; and how to reach you. A short proof of concept helps. Please do not include real customer code or data.
- How we respond
- We acknowledge your report as soon as we can, keep you updated while we investigate and fix, and tell you when it is resolved. We credit you if you want to be credited.
- Safe harbor
- If you act in good faith under this policy, we will not take legal action against you or ask anyone else to. Good faith means: test only against accounts and repositories you own or have permission to use, do not access, change or keep other people's data beyond what proves the issue, do not degrade the service, and give us reasonable time to fix before you disclose publicly. This policy covers Aevral only: it does not authorize testing of third-party services such as GitHub, model providers or hosting providers, which have their own policies. It binds Better ISMS only and cannot bind public authorities or other parties.
- Rewards
- We do not run a bug bounty and do not pay for reports.