Responsible disclosure

Security

Security reports are taken seriously and should be sent privately to security@craftvalestudio.com.

Private reporting channel

Found a security issue?

Send the details directly to our security inbox

Email security

Responsible disclosure guidance

Please:

  • Describe the affected application or service
  • Include clear reproduction steps
  • Explain the potential impact
  • Avoid accessing or modifying data that does not belong to you
  • Do not publicly disclose an unresolved vulnerability
  • Allow reasonable time for investigation and remediation

We aim to acknowledge valid security reports within 2 business days

Current security approach

  • Least-privilege access
  • Scoped credentials
  • Multi-factor authentication for administrative services
  • Separation of development and production environments where applicable
  • Dependency and vulnerability review
  • Minimal collection and retention of customer data
  • Incident investigation and customer communication where required