Skip to main content
๐ŸšจEarly AccessOrvoq is currently in early access. Expect occasional rough edges as we test, refine, and prepare for launch.
Trust Center / Responsible Disclosure
Responsible Disclosure

We take security reports seriously.

We welcome help from the research community in keeping Orvoq and our customers safe. If you believe you've found a security vulnerability in Orvoq, please report it to us privately so we can investigate and fix it before it's disclosed publicly.

Last reviewed: August 2026
01

How to report

  • โœ“A description of the vulnerability and its potential impact
  • โœ“Step-by-step instructions to reproduce it (proof-of-concept code, screenshots, or a video are helpful but not required)
  • โœ“The URL, endpoint, or affected component
  • โœ“Any tools or scripts used, so we can distinguish your testing traffic from an attack
If your report involves sensitive details, you can request our PGP key for encrypted email before sending.
02

What you can expect from us

1
Within 2 business days

Acknowledgment

We confirm we've received your report and it's in our queue.

2
Within 5 business days

Initial assessment

Our severity rating and next steps, communicated directly to you.

3
Ongoing

Regular updates

For the duration of the investigation and remediation โ€” you won't be left wondering where things stand.

4
On resolution

Credit, if you want it

Once the issue is fixed and disclosed, we maintain a hall-of-fame acknowledgments list for researchers who report in good faith.

โœ“
Always

No legal action against good-faith research

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy.

03

Scope

โœ“ In scope

  • *.orvoq.ai and subdomains, including the web application, marketing site, and API
  • Orvoq mobile or desktop clients, if applicable
  • Infrastructure and integrations we operate directly

โœ• Out of scope

  • Third-party services and integrations we don't control (report those to the vendor directly)
  • Denial-of-service or resource-exhaustion attacks
  • Social engineering, phishing, or physical attacks against Orvoq staff or offices
  • Automated vulnerability scanning generating significant volume without a specific, validated finding
  • Issues requiring physical access to a victim's device, or a jailbroken/rooted device
  • Missing security headers or best-practice recommendations without a demonstrated, exploitable vulnerability
  • Reports involving already-known or previously-reported vulnerabilities
04

Ground rules

To keep testing safe for everyone:

1

Only test against accounts and data you own or have explicit permission to test with. Don't access, modify, or exfiltrate another customer's data โ€” including through a demonstrated cross-tenant vulnerability. Stop at proof of concept.

2

Don't run automated scanners at a volume that could degrade service for other customers.

3

Give us a reasonable window to investigate and remediate before any public disclosure. We'll be transparent with you about progress and timeline if we need more.

4

Don't access, download, or retain more data than necessary to demonstrate the issue, and delete anything you did access once the report is filed.

90days from acknowledgment โ€” the disclosure window we ask for before any public write-up.

We evaluate every report on its merits and will always err on the side of working with a researcher who reported in good faith, even where the letter of these rules wasn't followed perfectly.

05

Recognition

No paid bug bounty โ€” but real credit, if you want it.

We don't currently run a paid bug bounty program. Researchers who report a valid, previously-unknown vulnerability are credited (with permission) in our acknowledgments list and are welcome to note the finding on their own portfolio once it's fixed and disclosed.