← Security
Security

Vulnerability Disclosure Policy

Last updated: August 25, 2026

We welcome good-faith security research. This policy explains how to test responsibly, what to include in a report, and what you can expect from Ervona. We do not currently operate a paid bug bounty program.

1. Reporting a vulnerability

Email security@ervona.ai. Please include the affected URL, extension version or product surface, steps to reproduce, the security impact, and any proof of concept that helps us verify the issue. Remove secrets and personal data that are not necessary to demonstrate the finding.

If you encounter customer data or credentials, stop testing, do not copy or retain them, and tell us immediately. Please allow us a reasonable opportunity to investigate and correct a confirmed issue before public disclosure.

2. In scope

3. Out of scope

4. Our response targets

5. Safe harbor

When research is conducted in good faith and follows this policy, Ervona will treat it as authorized security research and will not initiate legal action against the researcher for that work. If a third party initiates action related to compliant research, we will make it clear that the activity was conducted under this policy. This safe harbor does not bind third parties or excuse violations of law.

6. Coordinated disclosure

We ask that you keep a report confidential until we confirm a fix or agree on a disclosure date. We aim to coordinate disclosure within 90 days, but complex fixes, active exploitation, or customer safety may require a different timeline. We will credit researchers who want recognition, unless legal or privacy concerns prevent it.

7. No bounty commitment

Ervona does not currently promise monetary rewards. If we offer a discretionary reward for a report, that decision does not create an obligation for other reports.

8. Contact

security@ervona.ai

Ervona LLC
7901 4th St N, STE 300
St. Petersburg, FL 33702, USA