Skip to content
/ veriqa Public

Security: Ti-B2/veriqa

Security

SECURITY.md

Security Policy

Veriqa is an authentication product. Security reports receive priority.

Reporting a vulnerability

Do not report a vulnerability in a public issue, pull request or chat. Report privately by email to alert@veriqa.app. Do not use this address for support or licensing questions. The same contact is published in machine-readable form at https://veriqa.app/.well-known/security.txt (RFC 9116).

Include the affected component and version, deployment mode, impact, reproduction steps and a proof of concept where reasonably safe.

Safe harbor

We consider research conducted in good faith and consistently with this policy to be authorized by us for systems and accounts that we own or control. We will not initiate or support legal action based solely on accidental, good-faith violations of this policy, provided the researcher stops, avoids harm, promptly reports the issue and cooperates on remediation.

This statement cannot authorize access to a customer's, user's or other third party's system. Researchers must obtain permission from the owner or operator of every system tested and comply with applicable law. It also does not authorize privacy violations, social engineering, denial of service, physical attacks, persistence, data destruction, unnecessary access to personal data, or retention or disclosure beyond what is needed to report the issue.

If uncertain whether activity is authorized, contact us before proceeding.

Response targets

Stage Target
Acknowledgement within 3 business days
Initial assessment within 7 business days
Fix or mitigation plan communicated within 30 days after triage

These are good-faith operational targets, not service levels, warranties, guarantees or contractual commitments. Complexity, third-party dependencies and reporter responsiveness may affect timing.

Coordinated disclosure

Please allow a reasonable remediation period before public disclosure. We normally aim to coordinate disclosure within 90 days, but may agree on a shorter or longer period based on severity, active exploitation, patch availability and affected users. This is a request for cooperation, not a confidentiality agreement, unless separately agreed in writing.

No bug bounty or payment is offered unless expressly agreed in writing before the work. We may credit a reporter in release notes with their consent; anonymous reporting and no-credit requests are respected.

Personal data

We use contact details, report contents and related communications to receive, investigate, remediate and document security reports, protect users and establish or defend legal claims. Access is limited to people who need it. Do not submit personal data or production records beyond what is necessary; redact or minimize them where possible. Data may be stored or accessed where the maintainer and service providers operate, subject to applicable law. Requests concerning report data may be sent to devs@veriqa.app.

Supported versions

Until the first stable release, fixes are made in the latest released version. A version support table will be published with the first stable release.

There aren't any published security advisories