Scope
This policy covers evolvlabs.ai and EvolvLabs-operated infrastructure. Our products publish their own disclosure policies, which govern testing against those services:
- The DaycareLogix responsible disclosure policy covers the DaycareLogix service and daycarelogix.com.
- The Exolvra security & disclosure policy covers the Exolvra platform and exolvra.ai.
If you're not sure where a report belongs, send it to security@evolvlabs.ai and we'll get it to the right team.
How to report
Email security@evolvlabs.ai with:
- A description of the issue and the affected component or URL.
- Steps to reproduce, and a proof-of-concept if you have one.
- Your assessment of the impact.
- How you'd like to be credited, if the report leads to a fix and you want recognition.
You'll get an acknowledgment within three business days, updates while we validate and fix the issue, and a note when it's resolved. We'll also coordinate the timing of any public disclosure with you.
Ground rules
Act in good faith, and specifically:
- Never access, download, or retain records that are not yours.
- Don't degrade service for others. No denial-of-service testing, and no automated scanning heavy enough to create real load.
- No social engineering of EvolvLabs staff or our customers' staff, and no physical intrusion.
- Test only against your own accounts and data; do not test against customer systems or self-hosted customer deployments.
- Give us a reasonable window to remediate before any public disclosure.
Safe harbor
If you follow this policy in good faith, we will not pursue legal action against you for your research. This protection does not extend to violations of the ground rules above or to testing conducted against customer systems without the customer's authorization.
security.txt
This policy is referenced from /.well-known/security.txt per RFC 9116.