Security
How to report a security issue, what to include, and the boundaries of responsible research — kept short and honest rather than padded with certifications we do not hold.
Security at Veldarium
We treat security as an engineering responsibility, not a marketing claim. This page covers how to report a security issue in the public website or the authenticated product. It intentionally does not publish exploitable architecture detail. For the fuller registry of what is implemented, synthetic, or explicitly not claimed — including our explicit non-claims around certifications and government status — see Trust.
Reporting a security issue
Email chris@veldarium.com with the subject line starting “Security:”. This inbox is read directly by the founder.
A useful report includes:
- the affected URL, endpoint, or system;
- a clear description of the issue and its potential impact;
- step-by-step reproduction information;
- any supporting evidence (request/response samples, screenshots, logs) with sensitive values redacted.
Sensitive information in reports
Please do not include more than necessary to demonstrate the issue. In particular, do not send us credentials, other people’s data, classified information, Controlled Unclassified Information (CUI), or export-controlled technical data by email. If a finding genuinely requires sharing something like that to be understood, say so first and we will arrange an appropriate way to receive it — do not send it to this inbox unprompted.
Responsible research
We welcome good-faith security research conducted within reasonable boundaries. Do not:
- run destructive tests or attempt to degrade or deny service;
- exfiltrate, retain, or further access data beyond what is needed to demonstrate an issue;
- attempt social engineering against Veldarium personnel or any third party;
- attempt physical access to any facility or hardware; or
- access, modify, or attempt to access another user’s account or data.
This page describes our expectations for responsible research; it is not a legal safe-harbor commitment, and we have not published one. If that matters to your research, ask before you start.
No bounty program
Veldarium does not currently operate a paid bug-bounty program. We are grateful for responsible reports regardless, and will acknowledge them.
Response expectations
Reports are reviewed personally by the founder. We do not currently commit to a specific response-time window — we will acknowledge your report and follow up with next steps as the investigation allows.
Security claims
We do not describe Veldarium as unhackable, military-grade, government-grade, or certified to any security standard we have not actually obtained. Our current, explicit non-claims — including that we hold no SOC 2, ISO 27001, FedRAMP, or equivalent certification today — are listed on Trust.
security.txt
This reporting path is also published in machine-readable form at /.well-known/security.txt, following the common convention for automated security tooling.