Security policy
Reporting a vulnerability
Email security@sovrnti.io.
That mailbox reaches a human directly. Security reports never enter our support helpdesk and are never read by an automated agent.
Please do not open a public GitHub issue for a security problem.
What to include
| Item | Why |
|---|---|
| The affected host or endpoint | sovrnti.io, graph.sovrnti.io, app.sovrnti.io |
| Steps to reproduce | So we can confirm it rather than guess |
| What an attacker gains | Helps us rank it against everything else open |
| Your preferred credit name | We name reporters unless you ask us not to |
What we commit to
| Stage | Target |
|---|---|
| Acknowledgement | 3 business days |
| First assessment | 10 business days |
| Fix or a dated plan | 90 days from acknowledgement |
These are targets, not contractual guarantees.
Safe harbour
We will not pursue legal action against anyone who reports a vulnerability in good faith, provided you:
- do not access, modify or delete data belonging to anyone else;
- do not degrade the service for other users;
- give us reasonable time to fix the issue before disclosing it publicly.
Supported versions
Sovrnti is a hosted service. We support the currently deployed version only. There are no maintained release branches.