Trust center

Vulnerability disclosure policy

How to report a security issue to Vectyr, what is in scope, and the safe-harbour terms we offer researchers.

Version
1.1
Last updated
August 11, 2026
Document owner
Lucas Taylor (CTO)
Classification
Public

Provides evidence for

  • ISO/IEC 29147
  • SOC 2 CC7
  • NIST CSF 2.0 RS

Download Vulnerability disclosure policy as PDF

Reporting an issue

Email trust@vectyr.co, which reaches all three founders. Please include enough detail for us to reproduce the issue: the affected URL or component, the steps involved, what you observed, and why you believe it is a security problem. Screenshots or a short recording help. If you need to send something sensitive, say so and we will arrange an encrypted channel.

You do not need to have a formal relationship with Vectyr to report something, and we do not require you to accept an NDA to tell us about a vulnerability.

What you can expect from us

We acknowledge reports within one business day. Within five business days we will confirm whether we have reproduced the issue and give you our initial severity assessment.

We then keep you updated at least every ten business days until the issue is resolved. Our target remediation windows, measured from confirmation, are 7 days for critical issues, 30 days for high, 90 days for medium, and best-effort for low, with the same targets we hold ourselves to internally in Vulnerability and patch management.

We will tell you when the issue is fixed. If you would like credit we are happy to acknowledge you by name or handle; if you would rather stay anonymous, that is fine too. We will not name you without your agreement.

If we disagree that a report is a vulnerability, we will explain our reasoning rather than closing it silently.

Scope

In scope: vectyr.co and its subdomains, the Vectyr trust center including its NDA gate, and any application Vectyr operates for a client where that client has authorized your testing in writing.

That last condition is not a formality. Client systems process operational and research data, and in some cases relate to critical infrastructure. Testing them without the client’s authorization can trigger a genuine incident response, disrupt real operations, and expose you to legal risk we cannot waive on the client’s behalf. If you believe you have found an issue in a client deployment, report it to us and we will coordinate with the client.

Out of scope: our marketing site’s third-party dependencies where the issue lies with the provider rather than our configuration, and the categories listed below.

Things we already know are not vulnerabilities

To save your time: missing security headers with no demonstrated exploit; the absence of rate limiting on endpoints where we have accepted the risk; reports generated solely by an automated scanner with no validation; social engineering of Vectyr staff or clients; physical attacks; denial of service through volume; theoretical attacks requiring a compromised client device or a man-in-the-middle position on the user’s own network; email configuration findings that do not lead to spoofable mail; software version disclosure; and self-XSS requiring the victim to paste a payload.

Reports of confirmed credential leaks, exposed secrets, authentication or authorization bypass, data exposure across tenant boundaries, or anything permitting access to client data are always in scope and always urgent.

Rules of engagement

Please do not access, modify, or exfiltrate data that is not yours. If you encounter client data, stop, do not retain a copy, and tell us what you saw so we can assess the exposure. Do not degrade service availability. Do not use social engineering, physical intrusion, or attacks against our staff or clients. Do not publicly disclose before we have had a reasonable chance to remediate, and let us agree a timeline together.

Use only test accounts you created yourself. If you need a test account in the trust center gate, request access through the normal form.

Safe harbour

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your activity as authorized under applicable computer-misuse law. If a third party brings action against you for research conducted in line with this policy, we will make that authorization clear.

Good faith means: you stayed within scope, you stopped when you encountered someone else’s data, you did not degrade service, you gave us a reasonable window before disclosure, and you did not use your access for any purpose beyond demonstrating the vulnerability.

We do not run a paid bug bounty. What we do offer is a direct line to the people who will fix it, an acknowledgement within one business day, credit if you want it, and a note telling you exactly what we changed.

If you are a client reporting an incident

Clients with an active engagement should use the escalation path in their engagement documentation, which reaches us faster than this mailbox. Our commitments on detection, containment, and notification timelines are in the incident response plan.