Security
We take the security of CoreVecta apps seriously - especially the offline trust model behind them: signed license tokens, verify-before-open packs, and fail-closed entitlements. We welcome good-faith security research and will work with reporters to fix issues.
1. How to report
Email security@corevecta.com. Please include a description, the affected app/version/platform, reproduction steps or a proof of concept, and the impact. Do not include third parties' personal data in your report. We will acknowledge receipt and keep you updated.
2. Scope
In scope: the CoreVecta apps and their browser extensions; the stateless license issuer service; the cryptographic trust model (license forgery, entitlement bypass, pack signature bypass, trust-anchor confusion, revocation bypass, key handling); and privacy issues (any unexpected data collection, transmission, or network behaviour contrary to what an app's product page or the Privacy Policy states).
Out of scope: attacks requiring a physical or rooted device or a compromised OS; social engineering, physical attacks, and issues in third-party services (Google Play, our Merchant of Record) - report those to the respective party; reports from automated scanners without a demonstrated, exploitable impact; denial of service via volumetric flooding.
3. Safe harbour
We will not pursue or support legal action against researchers who, in good faith, make a reasonable effort to avoid privacy violations, data destruction, and service disruption; only interact with accounts or data they own or have explicit permission to test; do not exploit an issue beyond the minimum needed to prove it and do not exfiltrate data; and give us reasonable time to remediate before public disclosure. Activity consistent with this policy is considered authorised.
4. Coordinated disclosure
Please keep reports confidential until we confirm a fix or 90 days have passed, whichever is sooner. We are happy to coordinate a joint disclosure and to credit you, with your consent.
5. Response targets
- Acknowledge receipt: within 3 business days.
- Initial severity assessment: within 7 business days.
- Status updates: at least every 14 days until resolved.
6. Contact
Security reports: security@corevecta.com. General privacy questions: privacy@corevecta.com. Everything else: support@corevecta.com.