Legal
Vulnerability Disclosure Policy
Praeven Security welcomes reports of security vulnerabilities in the systems it operates. This policy states what is in scope, how to report, what to expect, and the protections available to researchers acting in good faith.
Last updated July 31, 2026
Scope
In scope
- praevensecurity.com and its subdomains
- The form submission endpoint at
/api/contact - Publicly reachable infrastructure operated by Praeven
Out of scope
- PrismVector. It is not publicly available and is not authorized for testing under this policy. Access is by written agreement only.
- Any customer system, network, or environment. Praeven cannot authorize testing of systems it does not own.
- Third-party services Praeven uses, including Cloudflare and Google. Report those to the provider under its own policy.
- Denial of service, resource exhaustion, and volumetric testing
- Social engineering of Praeven personnel, customers, or vendors
- Physical attacks against facilities or personnel
- Spam, unsolicited mail, or automated form submission at volume
- Findings that show only the absence of a hardening measure with no realistic path to impact, including missing headers without demonstrated exploitability, and unvalidated automated scanner output
Safe harbor
If you make a good-faith effort to comply with this policy during your research, Praeven will:
- Consider your research authorized under the Computer Fraud and Abuse Act and equivalent state law
- Consider it exempt from the anti-circumvention provisions of the Digital Millennium Copyright Act
- Waive any restriction in our Terms of Use that would otherwise prohibit the activity, for the limited purpose of that research
- Not pursue or support civil or criminal action against you, and not refer you to law enforcement
If a third party initiates legal action against you for activity conducted under this policy, we will make this authorization known.
This protection extends only to activity within the scope above, conducted in good faith. It does not authorize testing of any customer system, or of any system Praeven does not own.
If you are unsure whether something is in scope, ask before you act. A question sent to the address below will be answered.
How to report
Email security@praevensecurity.com with:
- A description of the vulnerability and where it exists
- The steps required to reproduce it
- What an attacker could achieve, in your assessment
- Any proof-of-concept material, with credentials and third-party data removed
Reports in English are preferred. You may report anonymously.
What to expect
| Stage | Target |
|---|---|
| Acknowledgment of your report | 3 business days |
| Initial assessment and triage decision | 10 business days |
| Status update while remediation is in progress | Every 15 business days |
| Remediation of a confirmed finding | Based on severity, communicated at triage |
Praeven is a small company. These are commitments, and where one is going to be missed you will be told rather than left waiting.
Guidelines
- Use only your own accounts and test data
- Stop as soon as a vulnerability is confirmed. Do not pivot further, escalate beyond what is needed to demonstrate impact, or access data belonging to anyone else
- Do not modify or delete data
- Do not degrade availability for other users
- If you encounter personal or confidential data, stop immediately, report it, and do not retain, copy, or disclose it
- Allow reasonable time for remediation before disclosing publicly
Disclosure
We support coordinated disclosure. Tell us if you intend to publish and we will agree a timeline. Ninety days from acknowledgment is a reasonable default, and an extension will be requested only with a stated reason.
You will be credited by name or handle in any advisory, unless you prefer otherwise.
No bounty
Praeven does not currently operate a paid bug bounty. Reports are acknowledged, credited, and acted on, but no monetary reward is offered. This is stated plainly so that no one spends time under a mistaken assumption.
Prepare. Anticipate. Protect.