Vulnerability Disclosure Policy
Last updated: August 25, 2026
We welcome good-faith security research. This policy explains how to test responsibly, what to include in a report, and what you can expect from Ervona. We do not currently operate a paid bug bounty program.
1. Reporting a vulnerability
Email security@ervona.ai. Please include the affected URL, extension version or product surface, steps to reproduce, the security impact, and any proof of concept that helps us verify the issue. Remove secrets and personal data that are not necessary to demonstrate the finding.
If you encounter customer data or credentials, stop testing, do not copy or retain them, and tell us immediately. Please allow us a reasonable opportunity to investigate and correct a confirmed issue before public disclosure.
2. In scope
https://ervona.aiand first-party subdomains operated by Ervona.- The Ervona Chrome extension published under extension ID
oacjiobmmngobojphebimlhgaoaidibm. - Ervona-owned APIs and authentication, authorization, tenant-isolation, credential-handling, and data-exposure issues.
3. Out of scope
- Third-party services, websites, or infrastructure not controlled by Ervona.
- Social engineering, phishing, physical attacks, spam, denial of service, or tests that degrade service for others.
- Automated scanning that creates excessive traffic, account creation, email, SMS, or support requests.
- Reports based only on missing best-practice headers, version strings, rate limits without demonstrated impact, or issues requiring an already-compromised device.
- Accessing, modifying, deleting, or retaining another person's data beyond the minimum needed to prove an issue.
4. Our response targets
- Acknowledgment: within three business days.
- Initial triage: within seven business days.
- Progress updates: at least every fourteen days while a confirmed report remains open.
- Remediation: prioritized by severity and exploitability. We will share a target after triage rather than promise a deadline before understanding the issue.
5. Safe harbor
When research is conducted in good faith and follows this policy, Ervona will treat it as authorized security research and will not initiate legal action against the researcher for that work. If a third party initiates action related to compliant research, we will make it clear that the activity was conducted under this policy. This safe harbor does not bind third parties or excuse violations of law.
6. Coordinated disclosure
We ask that you keep a report confidential until we confirm a fix or agree on a disclosure date. We aim to coordinate disclosure within 90 days, but complex fixes, active exploitation, or customer safety may require a different timeline. We will credit researchers who want recognition, unless legal or privacy concerns prevent it.
7. No bounty commitment
Ervona does not currently promise monetary rewards. If we offer a discretionary reward for a report, that decision does not create an obligation for other reports.
8. Contact
Ervona LLC
7901 4th St N, STE 300
St. Petersburg, FL 33702, USA