We take security seriously. If you've found a vulnerability, we want to hear from you.
At Invoist, we value the security community and welcome responsible disclosure of vulnerabilities. This policy outlines how to report security issues and what you can expect from us.
We encourage security researchers to responsibly disclose vulnerabilities to us before making them public. We commit to working with you to understand and address legitimate security issues promptly and transparently.
The following are in scope for security research:
The following activities are not permitted and are out of scope:
If you've discovered a security vulnerability, please email us with the following information:
When you submit a vulnerability report:
We will acknowledge receipt of your report within 3 business days.
We will investigate and assess the vulnerability, keeping you informed of our progress.
We will work to fix confirmed vulnerabilities as quickly as possible.
With your permission, we will publicly acknowledge your contribution.
We will not pursue legal action against security researchers who:
We do not currently offer a paid bug bounty program. However, we are happy to publicly acknowledge your contribution on this page if you report a valid vulnerability that we confirm and fix. Please let us know if you'd like to be credited.
We would like to thank the following security researchers for responsibly disclosing vulnerabilities:
No reports yet. Be the first to help us improve our security!