Responsible Disclosure Policy
Sovetta Technologies LLC Version 1.1 — Effective July 3, 2026
Sovetta builds software that financing companies trust with sensitive financial documents. Security is core to that trust, and we value the work of security researchers who act in good faith. If you believe you have found a vulnerability in our systems, we want to hear from you — and this Policy tells you how to report it, what is in scope, and the legal safe harbor we extend to good-faith research.
1. How to Report
E-mail [email protected] with the subject line "SECURITY". Please include, to the extent you can:
- A summary of the vulnerability and its class (e.g., authentication bypass, injection, access-control failure);
- The affected URL, endpoint, or component;
- Step-by-step reproduction instructions and any proof-of-concept;
- Your assessment of the impact (what data or functionality is exposed);
- How you would like to be credited, if at all.
We will acknowledge your report within 3 business days, keep you informed of our progress, and tell you when the issue is resolved. We ask that information you share with us about a vulnerability be shared unconditionally.
2. Scope
In scope: all internet-facing systems owned or operated by Sovetta, including our websites, the Platform's web dashboards and login, and its APIs.
In scope vulnerability classes include, without limitation: authentication or session-management flaws; access-control failures (including any way for one seat or organization to read another's data); injection (SQL, command, template); cross-site scripting and request forgery; server-side request forgery; insecure file handling in the document-intake pipeline; and privilege escalation.
Out of scope:
- Third-party services we use but do not operate (report those to the vendor);
- Denial-of-service, volumetric, or resource-exhaustion testing of any kind;
- Social engineering, phishing, or physical intrusion against Sovetta, its personnel, or its customers;
- Spam, credential stuffing, or brute-force attacks against login or password-reset endpoints;
- TLS/SSL configuration reports without a demonstrated practical impact;
- Missing security headers,
security.txt, or best-practice suggestions without an exploitable vulnerability; - Reports generated solely by automated scanners without validation;
- Vulnerabilities requiring a stolen or shared credential to exploit (though we do want to know about credential compromises — see the Acceptable Use Policy).
3. Rules of Engagement
While researching, you must:
- Do no harm. Do not access, modify, delete, or exfiltrate data that is not yours. If a proof of concept requires demonstrating data access, stop at the minimum needed to prove the issue (e.g., record names or counts, not contents) and tell us immediately.
- Limit exploitation to what is necessary to demonstrate the vulnerability exists. Do not pivot, persist, or install anything.
- Do not degrade the service for its users.
- Use only accounts you own or are explicitly authorized to use for testing.
- Keep the vulnerability confidential until we confirm it is resolved, and do not publicly disclose without our written agreement (we are reasonable — we support coordinated disclosure and researcher credit).
- Make no demand for payment as a condition of disclosure, and do not threaten publication to extract compensation. (We may thank good-faith researchers at our discretion, but this Policy is not a bug-bounty contract.)
- Comply with all applicable laws.
4. Safe Harbor
If you make a good-faith effort to research and report a vulnerability in accordance with this Policy:
- We will not pursue or support legal action against you for your research or your report, including under the Computer Fraud and Abuse Act or analogous state laws, and we waive any claim under our Terms of Service for the specific acts of good-faith research conducted consistent with this Policy;
- We will consider your research authorized under applicable anti-hacking and anti-circumvention laws to the maximum extent we are able to authorize it;
- If a third party initiates legal action against you for activity conducted in accordance with this Policy, we will make it known that your actions were conducted in compliance with it.
This safe harbor does not apply to research that violates the Rules of Engagement, harms our users or their data, or breaks laws we cannot authorize you to break.
5. Our Commitments
- Acknowledge within 3 business days; triage promptly; prioritize by severity;
- Keep you informed and treat you as a partner, not an adversary;
- Credit you (with your consent) once the issue is fixed;
- Never retaliate against good-faith reports.
Sovetta Technologies LLC · Report security issues: [email protected] (subject "SECURITY")