Business
Security and Vulnerability Reporting
Security controls, safe testing boundaries, and how to report a vulnerability.
- Last updated
- September 5, 2026
- Operator
- Colver.im
Security approach
Colver uses defence in depth: verified identity, fail-closed production configuration, tenant and principal isolation, private object storage, storage quotas, encrypted write-only secrets, scoped tools, explicit approvals, bounded uploads, request limits, short-lived browser sessions, and scrubbed tracing.
Security depends on the entire workflow. Users must protect their identity account, connected services, devices, recovery methods, and approvals.
Report a vulnerability
Email help@colver.im with the subject “Security report”. Include the affected URL or component, reproducible steps, impact, and any safe supporting evidence. Do not include another person's personal data or an active secret unless necessary; ask for a secure transfer method first.
We will acknowledge a useful report, investigate, and keep the reporter informed when practical. Colver does not currently promise a bounty or a fixed response deadline.
Safe testing boundaries
- Use only accounts, agents, files, secrets, and connected services you own or are authorised to test.
- Do not access, retain, change, or disclose another person's data.
- Do not use denial of service, automated high-volume traffic, spam, social engineering, physical attacks, or destructive payloads.
- Stop when you confirm a vulnerability. Do not establish persistence or move laterally.
- Give us a reasonable opportunity to fix a verified issue before public disclosure.
Account or data incident
If you believe your account or connected service is compromised, revoke the external connection, secure the identity account, stop affected agents, and contact us. For a suspected personal-data incident, identify the relevant workspace, time, data type, and affected people without sending unnecessary sensitive content.