# Vorel security disclosure policy (RFC 9116). # https://www.rfc-editor.org/rfc/rfc9116 # # If you've found a vulnerability, please email us — we read and triage # every report within 1 business day. We do not run a paid bug-bounty # program (yet), but we acknowledge confirmed reporters in our public # changelog with permission. # # DO submit reports privately to the address below. Public disclosure # before we've had a chance to remediate puts other Vorel customers at # risk and is contrary to coordinated disclosure norms. Contact: mailto:security@vorel.ai Expires: 2027-05-11T00:00:00Z Preferred-Languages: en, ar Canonical: https://app.vorel.ai/.well-known/security.txt Policy: https://app.vorel.ai/legal/security-policy