How to report
If you think you've found a security vulnerability in Avertari - the app at app.avertari.io, our websites, or our infrastructure - email security@avertari.io with enough detail for us to reproduce it. Our security.txt follows RFC 9116.
Scope
- In scope:
*.avertari.ioand the Avertari application. - Out of scope: denial of service, social engineering, physical attacks, spam or rate-limit findings without a security impact, and reports from automated scanners without a demonstrated issue.
What we ask
- Give us reasonable time to fix the issue before disclosing it publicly. We aim for 90 days and will agree a date with you.
- Only test against accounts and data you own. Don't access, change or keep other people's data - if you reach any, stop and tell us.
- Don't degrade the service for other users.
What we commit to
- We'll acknowledge your report within 3 business days and keep you updated until it's resolved.
- We won't pursue legal action over research that follows this policy in good faith.
- With your permission, we'll credit you once the issue is fixed.