Responsible Disclosure Policy

Aleverum takes the security of its website, platform, customer information and product-data workflows seriously. We welcome good-faith reports that help us identify and address potential vulnerabilities. 

1. How to report 

Email legal@aleverum.com with: 

  • A clear description of the suspected vulnerability; 
  • The affected page, endpoint, workflow, account type or service; 
  • Steps to reproduce the issue where possible; 
  • Screenshots, logs or supporting information that do not expose unnecessary personal or customer data; 
  • The potential impact; 
  • Your contact details and preferred method of follow-up. 

2. Good-faith research expectations 

Researchers must: 

  • Avoid accessing, changing, deleting, downloading or disclosing data beyond what is minimally necessary to demonstrate the issue; 
  • Avoid service disruption, denial-of-service testing, social engineering, spam, physical attacks or attempts against third-party personnel; 
  • Use only accounts and data they own or are authorised to test; 
  • Stop testing and notify Aleverum if sensitive, personal, confidential or customer data is encountered; 
  • Allow Aleverum a reasonable opportunity to investigate and remediate before public disclosure; 
  • Comply with applicable law. 

3. Out of scope 

  • Automated scanner reports without demonstrated impact; 
  • Clickjacking on pages with no sensitive actions; 
  • Missing headers or low-risk configuration observations without an exploitable impact; 
  • Rate-limit observations that do not create a material risk; 
  • Social engineering, phishing or physical-security tests; 
  • Denial-of-service, traffic flooding or resource exhaustion; 
  • Issues in third-party services not controlled by Aleverum, which should be reported to the relevant provider. 

4. Our response 

Aleverum will aim to acknowledge a credible report promptly, assess severity, request additional information where necessary, and provide reasonable progress updates. Response and remediation timeframes depend on severity, complexity, dependencies and operational risk. This policy does not create a contractual service level or obligation to pay a reward. 

5. Safe-harbour intent 

Where a researcher acts in good faith, complies with this policy and avoids privacy, confidentiality and service impacts, Aleverum does not intend to pursue legal action solely for the authorised security research. This statement does not authorise conduct prohibited by law or testing of third-party systems. 

6. Recognition and rewards 

Aleverum does not currently promise a bug bounty or public recognition. Any reward or acknowledgement is at Aleverum’s discretion and must be agreed in writing. 

7. Contact 

Security reports: legal@aleverum.com 

Effective date: August 6, 2026 | Last updated: August 6, 2026

Scroll to Top