Report a vulnerability
How to tell us about a security problem in Cenovel or this website, and what we do with your report. Write to [email protected].
Updated October 4, 2026
How to report
Email [email protected]. Please include:
- the Cenovel release, or the page of this website or the demo, that is affected;
- what you found and the steps to reproduce it;
- what an attacker could do with it, as you understand it;
- whether and how you would like to be credited.
We don’t publish an encryption key yet. If your report needs one, say so in a first message without the details, and we will arrange a way to send them.
What to expect
- A person reads every report and replies within 3 business days.
- We confirm the problem, rate it with CVSS, and tell you what we will do and roughly when.
- We fix it, publish a security advisory and notify districts, and credit you there if you wish.
For a vulnerability that is critical or being exploited, districts hear from us within one business day of our confirming it.
Scope
- In scope: the Cenovel appliance and console, site collectors, release bundles and the signing around them, this website and the live demo.
- Out of scope: a district’s own appliance, network and accounts. Never test against a district’s installation without the district’s written permission. Also out of scope: denial of service, social engineering, physical attacks and automated scanning that degrades this website.
Coordinated disclosure
- Give us 90 days to fix the problem before you publish, or until the fix is released, whichever comes first. If we need longer, we will say why.
- Don’t access, change or keep data that isn’t yours, and stop at the least access that shows the problem.
- We welcome good-faith research that follows this page, and will work with you rather than against you.
Pending legal review. This policy is in review with counsel; its wording may change, but the address and the way we handle reports will not.
There is no bug bounty.
See also: Security advisories · Lifecycle and support · security.txt