Responsible disclosure
Security
Security reports are taken seriously and should be sent privately to security@craftvalestudio.com.
Private reporting channel
Found a security issue?
Send the details directly to our security inbox
Responsible disclosure guidance
Please:
- Describe the affected application or service
- Include clear reproduction steps
- Explain the potential impact
- Avoid accessing or modifying data that does not belong to you
- Do not publicly disclose an unresolved vulnerability
- Allow reasonable time for investigation and remediation
We aim to acknowledge valid security reports within 2 business days
Current security approach
- Least-privilege access
- Scoped credentials
- Multi-factor authentication for administrative services
- Separation of development and production environments where applicable
- Dependency and vulnerability review
- Minimal collection and retention of customer data
- Incident investigation and customer communication where required