Found something? Tell us.
One address, a reply within two working days.
In plain words
Found a security problem in Provenize? Tell us at one address. You will hear back within two working days.
There is no cash reward. There is fair handling, and credit if you want it.
How to report
Email info@provenize.ai. Describe what you found and how to reproduce it — a rough note beats a polished report we get too late.
We confirm receipt within two working days and tell you what we did with it. If we disagree, you get the reasoning, not silence.
We publish no testing scope. If you want to know whether something is in bounds, ask first and we will answer — that is faster than guessing, for both of us.
What this is, and is not
- One contact addressBuiltno form, no portal, no triage queue
- Reply within two working daysBuiltfrom a person, not an autoresponder
- Credit if you want itBuiltnamed in the changelog, or not — your call
- PGP keyPlannedno published key yet; ask and we arrange a channel
- Coordinated disclosure timelinePlannedwritten down once there is a product to coordinate around
No bounty
There is no bug bounty and no payment. Saying so plainly is fairer than implying one exists.