Disclosure · Research · Safe Harbor

Responsible Disclosure

How to report a potential security vulnerability in an Emovur-operated system, what we ask of researchers while they test, and what we commit to in return.

Version
1.0
Last Updated
14th Aug, 2026
Initial Response
4 business hours
Safe Harbor
Applies
Researchers acting in good faith under this policy are covered by safe harbor
Section 01

Purpose

Emovur is committed to protecting the security of its platform, customers, and partners. We welcome responsible reports of potential security vulnerabilities and will investigate valid reports in a timely manner.

Section 02

Scope

This policy applies to systems Emovur operates directly.

In scope
  • Emovur-operated production systems
  • Public APIs
  • Web applications
  • Customer-facing services
Not covered
  • Third-party services
  • Systems Emovur does not operate
Section 03

Reporting

Send vulnerability reports to [email protected]. Complete reports are triaged fastest.

Please include
  • Affected asset
  • Description of the issue
  • Reproduction steps
  • Proof of concept, if available
  • Impact assessment
  • Your contact information
Section 04

Researcher Expectations

We ask researchers to test in a way that protects customers and their data.

While testing, please
  • Avoid accessing, modifying, or deleting customer data
  • Avoid service disruption
  • Respect user privacy
  • Stop testing once the issue is confirmed
  • Do not exploit beyond what demonstrates impact
Section 05

Out of Scope

The following are not accepted under this policy.

  • Social engineering
  • Phishing
  • Physical attacks
  • Denial-of-service testing
  • Spam
  • Issues requiring a compromised user device
  • Issues attributable solely to third-party platforms
Section 06

Our Commitment

Reports are acknowledged, investigated, and prioritized according to risk.

Initial response
Critical reports are acknowledged within 4 business hours.
Investigation
Valid reports are investigated and prioritized according to risk.
Remediation
Issues are remediated where appropriate, and reporters are updated as practical.
Section 07

Coordinated Disclosure

Please do not publicly disclose vulnerabilities until Emovur has had a reasonable opportunity to investigate and remediate them.

Coordinated disclosure is encouraged, and we are happy to agree a disclosure timeline with you.

Section 08

Safe Harbor

Emovur will not pursue legal action against researchers acting in good faith and in accordance with this policy.

Section 09

Rewards

Submission of a report does not create an obligation for compensation or participation in a bug bounty program unless separately announced.

Found a vulnerability?

Send it to [email protected] with reproduction steps and impact. Critical reports are acknowledged within 4 business hours.

© 2026 Audentrix Pvt. Ltd. All Rights Reserved.