Security

Vulnerability disclosure policy

If you find a security problem in Velsigil or on our websites, please tell us. We will work with you to fix it.

Last updated October 5, 2026

How to report

Email security@velsigil.com. Please include:

  • what you found and where (URL, component or software version)
  • the steps to reproduce it
  • the impact you think it has
  • how we can reach you, and whether you would like to be credited

Our contact details are also published in security.txt.

Scope

  • velsigil.com and www.velsigil.com (this website)
  • panel.velsigil.com: report problems you notice there, but do not run automated scanners against it, try to sign in, or test it actively. It is a production system.
  • The Velsigil software: the panel, the customer portal, the client API and the SDKs. Test it on an installation you run yourself.

Services run by other companies, such as our email provider or domain registrar, are out of scope; report problems there to the company that runs them.

Please

  • Comply with applicable law.
  • Do not access, change or delete data that does not belong to you. If you come across someone else’s data, stop, and tell us.
  • Do not degrade our services: no denial-of-service testing, no load or volume testing, no spam.
  • Do not use social engineering, phishing or physical attacks.
  • Do not ask for payment in exchange for not disclosing a problem.
  • Give us reasonable time to fix the problem before you share details with anyone else. We will agree a disclosure date with you; unless we agree otherwise, please wait 90 days from your report.

Safe harbor

If you research in good faith and follow this policy, we consider your research authorized, including under the Computer Fraud and Abuse Act and similar laws, and we will not take legal action against you or report you to law enforcement for it. For such research, we also waive any claim under section 1201 of the Digital Millennium Copyright Act for circumventing Velsigil’s license checks. If someone else takes legal action against you for research that followed this policy, we will make it known that your research was authorized.

What happens next

  • We aim to acknowledge your report within 3 business days.
  • We will confirm whether we can reproduce the problem and keep you informed while we fix it.
  • With your permission, we will credit you when we publish the fix.

We do not run a paid bug bounty at the moment.