Security

Report a vulnerability

How to tell us about a security problem in Cenovel or this website, and what we do with your report. Write to [email protected].

Updated October 4, 2026

How to report

Email [email protected]. Please include:

  • the Cenovel release, or the page of this website or the demo, that is affected;
  • what you found and the steps to reproduce it;
  • what an attacker could do with it, as you understand it;
  • whether and how you would like to be credited.

We don’t publish an encryption key yet. If your report needs one, say so in a first message without the details, and we will arrange a way to send them.

What to expect

  1. A person reads every report and replies within 3 business days.
  2. We confirm the problem, rate it with CVSS, and tell you what we will do and roughly when.
  3. We fix it, publish a security advisory and notify districts, and credit you there if you wish.

For a vulnerability that is critical or being exploited, districts hear from us within one business day of our confirming it.

Scope

  • In scope: the Cenovel appliance and console, site collectors, release bundles and the signing around them, this website and the live demo.
  • Out of scope: a district’s own appliance, network and accounts. Never test against a district’s installation without the district’s written permission. Also out of scope: denial of service, social engineering, physical attacks and automated scanning that degrades this website.

Coordinated disclosure

  • Give us 90 days to fix the problem before you publish, or until the fix is released, whichever comes first. If we need longer, we will say why.
  • Don’t access, change or keep data that isn’t yours, and stop at the least access that shows the problem.
  • We welcome good-faith research that follows this page, and will work with you rather than against you.

Pending legal review. This policy is in review with counsel; its wording may change, but the address and the way we handle reports will not.

There is no bug bounty.

See also: Security advisories · Lifecycle and support · security.txt

↑ ↓ to moveEnter to openEsc to close