Legal document
Vulnerability Disclosure and Security Policy
Version v2.0 · Effective Thursday, July 30, 2026
ResearchCave welcomes good-faith security research that follows this Policy.
Reporting
Send reproducible details, affected assets, impact, and supporting evidence to . Encrypt sensitive reports when a public key is provided.
Research rules
Avoid privacy violations, data destruction, service disruption, social engineering, physical attacks, denial of service, and access beyond what is necessary to demonstrate the issue.
Safe harbour
Research conducted in good faith and within this Policy will be treated as authorised to the extent ResearchCave can provide such authorisation. We aim to acknowledge, investigate, remediate, and credit reports on a risk-based schedule.