Email security@avelra.com. Please include: a description of the vulnerability, steps to reproduce, potential impact, affected URLs or components, and any evidence (screenshots, logs). Let us know if you would prefer encrypted communication.
Acknowledgement of receipt within 48 hours. Initial assessment and update within 7 working days. We will keep you informed until resolution. We will not pursue legal action against anyone reporting in good faith who complies with this policy (safe harbour).
This policy covers: one.avelra.com, avelra.com, the platform's public APIs and the official AVELRA ONE mobile applications. It does not cover third-party services (e.g. Revolut, Hostinger), which have their own policies.
DoS/DDoS attacks or testing that degrades the service. Accessing, modifying or deleting other users' data. Social engineering of staff or customers. Physical attacks. Public disclosure before we have resolved the issue. Exploiting a vulnerability beyond what is necessary to demonstrate its existence.
With your consent, we will publicly credit you as a contributor to AVELRA ONE's security. We do not currently offer monetary rewards (bug bounty), but every serious report is valued and acknowledged.
security@avelra.com — for security matters
AVELRA LTD, 7 Bell Yard, London WC2A 2JR · info@avelra.com