Security
Report issues privately.
Send suspected vulnerabilities to security@volelab.xyz. Include the affected surface, reproduction steps, likely impact, and evidence that can be shared safely.
Boundaries
- Do not access, alter, retain, or disclose private customer information.
- Do not use denial-of-service, social engineering, credential attacks, persistence, or destructive testing.
- Do not test third-party or production systems without written authorization.
- Stop when you encounter a secret, private record, cross-tenant exposure, or consequential effect.
What to expect
We aim to acknowledge a report within three business days, provide an initial assessment within seven business days, and coordinate remediation and disclosure. Good-faith, authorized research will not be retaliated against.
Machine-readable policy
The same contact and policy are published at /.well-known/security.txt.