Sovetta Technologies LLC
Legal Center / Responsible Disclosure Policy
Version 1.1 · Effective 2026-07-03 · Print / save as PDF

Responsible Disclosure Policy

Sovetta Technologies LLC Version 1.1 — Effective July 3, 2026

Sovetta builds software that financing companies trust with sensitive financial documents. Security is core to that trust, and we value the work of security researchers who act in good faith. If you believe you have found a vulnerability in our systems, we want to hear from you — and this Policy tells you how to report it, what is in scope, and the legal safe harbor we extend to good-faith research.


1. How to Report

E-mail [email protected] with the subject line "SECURITY". Please include, to the extent you can:

We will acknowledge your report within 3 business days, keep you informed of our progress, and tell you when the issue is resolved. We ask that information you share with us about a vulnerability be shared unconditionally.

2. Scope

In scope: all internet-facing systems owned or operated by Sovetta, including our websites, the Platform's web dashboards and login, and its APIs.

In scope vulnerability classes include, without limitation: authentication or session-management flaws; access-control failures (including any way for one seat or organization to read another's data); injection (SQL, command, template); cross-site scripting and request forgery; server-side request forgery; insecure file handling in the document-intake pipeline; and privilege escalation.

Out of scope:

3. Rules of Engagement

While researching, you must:

4. Safe Harbor

If you make a good-faith effort to research and report a vulnerability in accordance with this Policy:

This safe harbor does not apply to research that violates the Rules of Engagement, harms our users or their data, or breaks laws we cannot authorize you to break.

5. Our Commitments


Sovetta Technologies LLC · Report security issues: [email protected] (subject "SECURITY")

© 2026 Sovetta Technologies LLC · Legal Center · Privacy · Cookies · Report a vulnerability