Veriqa is an authentication product. Security reports receive priority.
Do not report a vulnerability in a public issue, pull request or chat. Report
privately by email to alert@veriqa.app. Do not use this address for support
or licensing questions. The same contact is published in machine-readable form
at https://veriqa.app/.well-known/security.txt (RFC 9116).
Include the affected component and version, deployment mode, impact, reproduction steps and a proof of concept where reasonably safe.
We consider research conducted in good faith and consistently with this policy to be authorized by us for systems and accounts that we own or control. We will not initiate or support legal action based solely on accidental, good-faith violations of this policy, provided the researcher stops, avoids harm, promptly reports the issue and cooperates on remediation.
This statement cannot authorize access to a customer's, user's or other third party's system. Researchers must obtain permission from the owner or operator of every system tested and comply with applicable law. It also does not authorize privacy violations, social engineering, denial of service, physical attacks, persistence, data destruction, unnecessary access to personal data, or retention or disclosure beyond what is needed to report the issue.
If uncertain whether activity is authorized, contact us before proceeding.
| Stage | Target |
|---|---|
| Acknowledgement | within 3 business days |
| Initial assessment | within 7 business days |
| Fix or mitigation plan communicated | within 30 days after triage |
These are good-faith operational targets, not service levels, warranties, guarantees or contractual commitments. Complexity, third-party dependencies and reporter responsiveness may affect timing.
Please allow a reasonable remediation period before public disclosure. We normally aim to coordinate disclosure within 90 days, but may agree on a shorter or longer period based on severity, active exploitation, patch availability and affected users. This is a request for cooperation, not a confidentiality agreement, unless separately agreed in writing.
No bug bounty or payment is offered unless expressly agreed in writing before the work. We may credit a reporter in release notes with their consent; anonymous reporting and no-credit requests are respected.
We use contact details, report contents and related communications to receive, investigate, remediate and document security reports, protect users and establish or defend legal claims. Access is limited to people who need it. Do not submit personal data or production records beyond what is necessary; redact or minimize them where possible. Data may be stored or accessed where the maintainer and service providers operate, subject to applicable law. Requests concerning report data may be sent to devs@veriqa.app.
Until the first stable release, fixes are made in the latest released version. A version support table will be published with the first stable release.