Skip to content

Security

Responsible disclosure

Found a weakness in Cryvanta's own systems? Tell us. We work in offensive security for a living, so we'll treat your report the way we'd want ours treated — seriously, and without drama.

Acknowledge
≤ 3 business days
Safe harbour
Good-faith research
Contact
security.txt

How to report

Email us, in plain terms

Send what you found to our security contact. There's no portal to fight and no form to fill — just a clear description we can act on.

hello@cryvanta.io

Include the affected asset, the steps to reproduce, and the impact you think it has. Please don't access more data than you need to demonstrate the issue, and don't degrade or disrupt the service. Our machine-readable contact is published at /.well-known/security.txt.

What to expect

An honest process, not an SLA we can't keep

We're a small team and we won't pretend otherwise. Here's what we can actually commit to.

  1. Step 01

    You send

    One email, no portal

    The affected asset, the steps to reproduce, and the impact you think it has.

  2. Step 02

    ≤ 3 days

    We acknowledge

    Business days, CET. A human confirms we have it and that it is being looked at.

  3. Step 03

    We triage

    In scope, or honestly not

    You get a straight answer on whether it is ours to fix and what we intend to do about it.

  4. Step 04

    We fix

    Updates until it closes

    We keep you posted as the work lands, and confirm with you once it is genuinely resolved.

  5. Step 05

    You're credited

    If you want to be

    With your permission, and never before the issue is closed. Some researchers prefer not to be named.

Scope

What we can act on

In scope

  • cryvanta.io and its subdomains
  • Infrastructure Cryvanta operates directly

Out of scope

  • Customer engagements and customer environments (report those to the customer)
  • Third-party services we use but don't operate
  • Volumetric or denial-of-service testing
  • Social engineering of our staff, partners, or customers

Safe harbour. If you make a good-faith effort to follow this policy — stay in scope, avoid privacy violations and service disruption, and don't exfiltrate or destroy data — we will not pursue or support legal action against you for your research, and we'll work with you to understand and resolve the issue quickly.

Reporting something urgent?

If you believe there's an active compromise of Cryvanta or a customer, say so in the subject line and we'll prioritise it.