Vulnerability Disclosure Policy
Last updated August 28, 2026
Vantaura Security builds security software, and we welcome reports from the security community. This policy explains how to report a vulnerability, what is in scope, and what you can expect from us.
Our commitment (safe harbor)
If you make a good-faith effort to comply with this policy during your research, we will:
- consider your research authorized, and not pursue or support legal action against you for accidental, good-faith violations of this policy; and
- work with you to understand and resolve the issue promptly.
This authorization does not extend to actions that violate the law, harm our users, or access or modify data that is not yours.
Scope
In scope — Vantaura’s own internet-facing assets:
vantaurasecurity.comand its subdomains- the customer portal and its APIs
/.well-known/security.txtand related site configuration
RelentLens product software. RelentLens is self-hosted — customers run it in their own environments, which are not in scope for testing. However, if you are a legitimate customer and discover a security vulnerability in the RelentLens software itself, we want to hear about it — report it through the contact below and we will handle it under coordinated disclosure. Do not test against any environment you do not own or have explicit permission to test.
Out of scope
Please do not:
- run denial-of-service (DoS/DDoS), volumetric, or load/stress tests;
- use social engineering, phishing, or physical attacks against Vantaura staff, users, or facilities;
- test third-party services we use (e.g., Cloudflare) — report those to the respective vendor;
- access, download, modify, or delete data that is not yours, or degrade our services for others; or
- test any customer’s self-hosted RelentLens deployment.
Reports that are typically not accepted on their own include missing best-practice headers with no demonstrated impact, automated-scanner output without a working proof of concept, rate-limiting nitpicks, and theoretical issues without a realistic exploit path.
How to report
Email security@vantaurasecurity.com. Please include:
- a clear description of the issue and its potential impact;
- the affected asset (URL/endpoint, or the product component and version);
- step-by-step reproduction, with a minimal proof of concept where possible; and
- any relevant logs or screenshots.
Report only what is necessary to demonstrate the issue. Do not include more personal or customer data than required, and stop and notify us immediately if you encounter personal data during your research.
What to expect from us
- Acknowledgement within 5 business days of your report.
- A triage assessment and severity determination, with updates on remediation progress.
- For issues in the RelentLens product, coordinated disclosure: we aim to remediate and, where appropriate, publish an advisory and notify affected customers within 90 days, coordinating timing with you.
Rewards
Vantaura Security does not operate a bug-bounty program and does not offer monetary rewards or public recognition for reported vulnerabilities. Good-faith reports are nonetheless welcomed and are handled in accordance with this policy.
Legal
This policy applies to good-faith security research only. It does not grant permission to act inconsistently with the law or applicable third-party terms. We may update this policy at any time. Governing law: Texas.