Security policy

Reporting a vulnerability

Email security@sovrnti.io.

That mailbox reaches a human directly. Security reports never enter our support helpdesk and are never read by an automated agent.

Please do not open a public GitHub issue for a security problem.

What to include

ItemWhy
The affected host or endpointsovrnti.io, graph.sovrnti.io, app.sovrnti.io
Steps to reproduceSo we can confirm it rather than guess
What an attacker gainsHelps us rank it against everything else open
Your preferred credit nameWe name reporters unless you ask us not to

What we commit to

StageTarget
Acknowledgement3 business days
First assessment10 business days
Fix or a dated plan90 days from acknowledgement

These are targets, not contractual guarantees.

Safe harbour

We will not pursue legal action against anyone who reports a vulnerability in good faith, provided you:

  • do not access, modify or delete data belonging to anyone else;
  • do not degrade the service for other users;
  • give us reasonable time to fix the issue before disclosing it publicly.

Supported versions

Sovrnti is a hosted service. We support the currently deployed version only. There are no maintained release branches.