Security

Responsible disclosure

If you've found a security issue in anything we run, we want to hear about it. This page explains how to report it, what to expect from us, and the safe harbor we extend to good-faith research.

Report to: security@evolvlabs.ai Last updated: July 31, 2026

Scope

This policy covers evolvlabs.ai and EvolvLabs-operated infrastructure. Our products publish their own disclosure policies, which govern testing against those services:

If you're not sure where a report belongs, send it to security@evolvlabs.ai and we'll get it to the right team.

How to report

Email security@evolvlabs.ai with:

  • A description of the issue and the affected component or URL.
  • Steps to reproduce, and a proof-of-concept if you have one.
  • Your assessment of the impact.
  • How you'd like to be credited, if the report leads to a fix and you want recognition.

You'll get an acknowledgment within three business days, updates while we validate and fix the issue, and a note when it's resolved. We'll also coordinate the timing of any public disclosure with you.

Ground rules

Act in good faith, and specifically:

  • Never access, download, or retain records that are not yours.
  • Don't degrade service for others. No denial-of-service testing, and no automated scanning heavy enough to create real load.
  • No social engineering of EvolvLabs staff or our customers' staff, and no physical intrusion.
  • Test only against your own accounts and data; do not test against customer systems or self-hosted customer deployments.
  • Give us a reasonable window to remediate before any public disclosure.

Safe harbor

If you follow this policy in good faith, we will not pursue legal action against you for your research. This protection does not extend to violations of the ground rules above or to testing conducted against customer systems without the customer's authorization.

security.txt

This policy is referenced from /.well-known/security.txt per RFC 9116.

Looking for our security architecture rather than the disclosure process? That lives in the Trust Center: tenant isolation, audit logging, framework alignment, and the shared responsibility model.