Security
Responsible disclosure
Found a weakness in Cryvanta's own systems? Tell us. We work in offensive security for a living, so we'll treat your report the way we'd want ours treated — seriously, and without drama.
- Acknowledge
- ≤ 3 business days
- Safe harbour
- Good-faith research
- Contact
- security.txt
How to report
Email us, in plain terms
Send what you found to our security contact. There's no portal to fight and no form to fill — just a clear description we can act on.
Include the affected asset, the steps to reproduce, and the impact you think it has. Please don't access more data than you need to demonstrate the issue, and don't degrade or disrupt the service. Our machine-readable contact is published at /.well-known/security.txt.
What to expect
An honest process, not an SLA we can't keep
We're a small team and we won't pretend otherwise. Here's what we can actually commit to.
Step 01
You send
One email, no portal
The affected asset, the steps to reproduce, and the impact you think it has.
Step 02
≤ 3 days
We acknowledge
Business days, CET. A human confirms we have it and that it is being looked at.
Step 03
We triage
In scope, or honestly not
You get a straight answer on whether it is ours to fix and what we intend to do about it.
Step 04
We fix
Updates until it closes
We keep you posted as the work lands, and confirm with you once it is genuinely resolved.
Step 05
You're credited
If you want to be
With your permission, and never before the issue is closed. Some researchers prefer not to be named.
Scope
What we can act on
In scope
- cryvanta.io and its subdomains
- Infrastructure Cryvanta operates directly
Out of scope
- Customer engagements and customer environments (report those to the customer)
- Third-party services we use but don't operate
- Volumetric or denial-of-service testing
- Social engineering of our staff, partners, or customers
Safe harbour. If you make a good-faith effort to follow this policy — stay in scope, avoid privacy violations and service disruption, and don't exfiltrate or destroy data — we will not pursue or support legal action against you for your research, and we'll work with you to understand and resolve the issue quickly.

Reporting something urgent?
If you believe there's an active compromise of Cryvanta or a customer, say so in the subject line and we'll prioritise it.