LEGAL · SECURITY · RESPONSIBLE DISCLOSURE
Report a
vulnerability.
Veritan welcomes responsible security research. This page describes how to report a suspected vulnerability and what to expect. No formal bug-bounty program is currently active. Reports are reviewed on a best-effort basis.
DISCLOSURE POLICY
Report. Coordinate. Do not invent authority we have not earned.
Security posture at Veritan means stating what is real. No formal certification, SOC 2, ISO 27001, or third-party security audit is represented as complete on this surface unless a publishable artifact exists. This policy represents current operating intent, not a legal guarantee.
NO BUG BOUNTY
Veritan does not currently operate a formal bug-bounty or vulnerability-rewards program. No financial reward is promised or implied for any report.
REPORTING CONTACT
Report suspected vulnerabilities to security@veritan.to with a subject beginning "SECURITY REPORT:". Include a description of the issue, steps to reproduce, and the potential impact you have identified. Reports are reviewed on a best-effort basis.
COORDINATED DISCLOSURE
Veritan requests that researchers allow a reasonable time to investigate and remediate before public disclosure. No specific timeline is guaranteed. Researchers who contact us before public disclosure are acting in good faith and will be treated accordingly.
SCOPE
In scope: veritan.to, api.veritan.to, and associated production infrastructure. Out of scope: third-party services (Supabase, Stripe, Vercel infrastructure), social engineering, physical attacks.
LIMITATIONS
This policy does not create an SLA, contract, safe-harbor commitment, or enforceable obligation. Veritan reserves the right to update or withdraw this policy at any time without prior notice. This page reflects current operating intent, not legal guarantee.