Responsible Disclosure
How to report a security vulnerability to Aventiq, what we expect from you, and what you can expect from us.
1. Our Commitment to Security
We take the security of our website and the data entrusted to us seriously. We welcome reports from security researchers who discover a vulnerability and disclose it to us responsibly, and we commit to working with you to understand and resolve the issue quickly.
2. Scope
This policy covers the public Aventiq website, its public forms and API endpoints, and the staff dashboard, all under aventiqgroup.com. It does not cover third-party services we use (such as Supabase, Google or our hosting provider) - please report issues with those directly to them - nor does it cover social engineering, physical access attempts, or denial-of-service testing against our infrastructure.
3. How to Report a Vulnerability
Email info@aventiqgroup.com with as much detail as you can provide: the type of issue, the steps to reproduce it, and its potential impact. Please do not include real personal data belonging to others in your report. A machine-readable summary of this contact is also published at /.well-known/security.txt.
4. Expected Behaviour
We ask that you:
- Give us a reasonable amount of time to investigate and remediate an issue before disclosing it publicly
- Avoid accessing, modifying or deleting data that isn't yours, beyond what's strictly necessary to demonstrate the issue
- Avoid actions that could degrade the availability of our services for other users
- Only interact with accounts and data you own or have explicit permission to test
5. Safe Harbour
We will not pursue legal action against, and will not report to law enforcement, any researcher who discovers and reports a vulnerability in good faith, in accordance with this policy. This safe harbour does not extend to actions taken outside the scope described above.
6. What to Expect From Us
We aim to acknowledge a report within 5 business days, keep you informed of our progress, and let you know once the issue has been resolved. We ask that you keep the details confidential until then. We do not currently operate a paid bug bounty program, but we're happy to credit researchers who wish to be acknowledged once a fix has shipped.
7. Contact
Security reports: info@aventiqgroup.com. See also /.well-known/security.txt.
Questions about our legal policies?
If you need clarification regarding our legal documents, data protection practices or partnership agreements, our team will be happy to assist you.
Contact Us