Found a security problem? Tell us.
We would much rather hear it from you than read about it later.
In scope
- This website
- The Vault For Us app
- Its API
- The operator console
Out of scope
- Findings that only apply to a self-hosted copy someone else set up
- Automated scanner reports with no shown impact
- Anything that needs physical access to a family's own device
How to report
Email support@aevoriscloud.com. The same address is in security.txt. Say what you did, what you saw, and enough for us to reproduce it. Please don't test against another family's data: if you need an account, create your own.
24 hours
to acknowledge your report
6 hours
to notify CERT-In after becoming aware of an incident, where Indian law requires it
72 hours
to tell affected families after becoming aware of a breach
Always
we tell you what we found and when it was fixed
Good-faith research. We won't take legal action against research that follows this page and respects other families' data. A formal safe-harbour statement will be published here.
Rewards. We don't run a paid bug bounty. If that changes, this page will say so.
Curious how it is all locked? Read how Vault For Us keeps things private.