Responsible Disclosure Policy
Effective
How to report a security vulnerability to Evolutions, what we ask of researchers, and the safe harbor you can rely on when you report to us in good faith.
1. Overview
Evolutions is building the financial plumbing our customers’ funds and investors will depend on, so we treat security as foundational. We know that no team finds everything itself, and we want security researchers to feel welcome pointing out what we missed.
This Responsible Disclosure Policy describes how to report a potential vulnerability in our systems, what we ask of you while you research it, and what you can expect from us in return. If you have found something, thank you in advance — the report itself is the valuable part, and we will treat it that way. Our machine-readable contact is also published in security.txt, per RFC 9116.
2. Scope
The following assets are in scope for research and reporting under this Policy:
- evolutionshq.com and www.evolutionshq.com — this website and everything served from it, including the contact endpoint;
- any future subdomain of evolutionshq.com, including our platform and its APIs once they are live; and
- our official open-source repositories, where present.
services provided by our vendors are not in scope through us — including our hosting and delivery infrastructure, our analytics relay, and the anti-spam service on our contact form. If you find an issue in one of those, please report it to that vendor’s own security program; if you are not sure whether something is ours or a vendor’s, send it to us anyway and we will route it.
3. Out of scope
We will review every report, but the following are out of scope for this Policy:
- denial-of-service or volumetric testing that degrades availability;
- social engineering or phishing of our employees, customers, or vendors;
- physical testing against our offices or data centers;
- vulnerabilities in third-party services, unless they expose Evolutions or customer data;
- findings from automated scanner output without a working demonstration of impact; and
- best-practice gaps with no exploitable impact — missing or weak security headers on their own, TLS configuration preferences, cookie flags without a demonstrated attack, and clickjacking on pages with no sensitive actions.
We also do not accept reports from individuals or entities subject to applicable sanctions, or from jurisdictions where receiving or acting on such a report is prohibited.
4. Ground rules
To stay within the safe harbor in Section 6, please:
- act in good faith and avoid harming our systems, our data, our customers, or their investors;
- test only against accounts and data you own or are explicitly authorized to use;
- do only what is necessary to demonstrate the vulnerability — no exploitation of the finding, no pivoting into other systems;
- stop and report immediately if you encounter data that is not yours. Do not access, copy, retain, or disclose it any further than the demonstration requires;
- keep the vulnerability confidential until we have remediated it or agreed otherwise with you in writing — do not disclose it publicly or to third parties before then;
- give us at least 90 days from your report before any public disclosure — if we need longer, we will ask, and tell you why; and
- do not use a finding to demand payment or any other consideration.
5. Reporting a vulnerability
Send your report to security@evolutionsmail.example.hq.com. One vulnerability per report, please, unless the findings chain into a single issue. As much as you can, include:
- a description of the vulnerability and where it lives (URL, endpoint, or component);
- step-by-step instructions to reproduce it, with commands, requests, or screenshots where they help;
- the potential impact — what an attacker could do with it;
- when you discovered it and how to reach you; and
- whether you would like to be acknowledged, and if so, how.
Please do not include sensitive data in your first message. If your report needs a confidential channel — for example, to share proof-of-concept material safely — say so, and we will arrange one in our reply.
6. Safe harbor
Security research conducted in good faith and in accordance with this Policy is authorized conduct. If you follow the ground rules in Section 4:
- we will not initiate legal action against you for your research or your report;
- if a third party initiates action against you for activities conducted under this Policy, we will take steps to make it known that you acted in accordance with it; and
- we will not ask you to sign a non-disclosure agreement before we receive your report.
This safe harbor is ours to give only for our own rights — we cannot waive the rights of our customers, their investors, or any other third party, and research that reaches their systems or data is not covered. Safe harbor does not extend to activity that is intentionally malicious or reckless, that goes beyond what is necessary to demonstrate a finding, or that demands consideration in exchange for silence.
7. Our commitments
When you report a vulnerability to us, we will:
- acknowledge receipt within one business day;
- triage and assess the report, and give you our initial determination, within five business days;
- remediate validated findings on a timeline driven by severity, and keep you informed of progress where you have left contact details;
- coordinate disclosure with you before anything goes public, once remediation is in place; and
- keep your identity confidential — we will not share who you are without your permission, except where the law compels us.
We may decide a reported issue is not a vulnerability, and we will tell you why. Where a finding turns out to be an active incident rather than a research question, it moves into our incident response process; we will still keep the reporter informed where we can.
8. Acknowledgment
We do not currently run a paid bug bounty program. What we do offer is a genuine thank-you: with your permission, we will credit researchers who help us secure the platform — and we will tell you plainly if and when a bounty program starts.
9. Contact
Security reports go to security@evolutionsmail.example.hq.com. That address is reserved for vulnerability reports — for everything else, including privacy questions, use the contacts in our Privacy Policy or the form on our home page.