Security
Coordinated disclosure
If you have found a security issue in the Venkai engine, in this website or in our infrastructure, we want to hear about it before anyone else does.
Report to
security@venkai.frA PGP key will be published here and in /.well-known/security.txt before launch. Until then, do not send exploit details you would not send in cleartext — describe the class of issue and we will arrange an encrypted channel.
What we commit to
- Acknowledgement within 3 working days.
- An assessment, with our severity rating and reasoning, within 10 working days.
- Credit in the fix notes if you want it, and silence if you prefer that.
- No legal action against good-faith research conducted within the scope below.
Scope
In scope: this domain and its subdomains, and the Venkai engine as distributed to you. Out of scope: denial of service, volumetric testing, social engineering of people, physical attacks, and findings from automated scanners submitted without a demonstrated impact.
Please do not access, modify or exfiltrate data that is not yours, and do not degrade service for others. If a proof of concept requires either, stop and describe what you would have done.
No bounty
We do not run a paid bounty programme. Saying so plainly is more useful than a page that implies one.