Report vulnerabilities to security@terravek.com. Our policy, PGP key and scope are published at https://www.terravek.com/.well-known/security.txt and at /legal/vulnerability-disclosure.html.

We acknowledge within 72 hours, provide an assessment within ten working days, and will keep you informed until the issue is resolved. We do not require you to sign anything before reporting.

We will credit you in the hall of thanks with your consent. Terravek does not currently run a paid bug bounty.