01
Report a vulnerability
Email [email protected] with the subject ‘Security disclosure’. Include the affected URL or product, a description of the issue and its potential impact, minimal steps to reproduce it, and your preferred contact details. Screenshots or a small proof of concept can help. Redact secrets and personal data. Ask us for a suitable transfer method before sending sensitive evidence.
02
Scope
This policy covers security issues in websites and services operated by Evokoa for Evokoa, WonderSearch, and Polygres. Test only systems we control, using accounts and data you own or are explicitly authorized to use. A linked third-party service, customer deployment, or provider’s infrastructure is not included. If ownership or permission is unclear, email us before testing.
03
Keep research safe
Use the minimum testing needed to demonstrate an issue. Do not disrupt availability, conduct denial-of-service attacks, use social engineering, access other customers’ accounts, alter or destroy data, install persistence, or extract data at scale. Stop immediately if you encounter another person’s data or confidential information, and report what happened without retaining or sharing that information.
This policy supports finding and reporting security defects. It does not authorize model extraction, distillation, training on responses, or attempts to reproduce proprietary technology for other purposes.
04
Coordinate disclosure
Report issues promptly and give us a reasonable opportunity to investigate and address them before sharing exploit details publicly. We will review reports, seek clarification when needed, and work with you on remediation and disclosure timing. Resolution depends on impact and complexity; this policy does not promise a fixed response or remediation deadline. There is no guaranteed payment or bounty.
05
Good-faith research
Evokoa authorizes only the limited security testing expressly permitted by this policy. To qualify, your activity must be conducted in good faith for the purpose of identifying and responsibly reporting a security vulnerability, remain within the stated scope, use the minimum testing necessary, and comply with the safeguards and disclosure requirements above. For activity that meets these conditions, Evokoa will not initiate legal action against you under rights or claims we control. This commitment covers only that qualifying activity, not unrelated or prohibited conduct.
Submitting a vulnerability report, describing an activity as research, or offering to disclose a vulnerability does not by itself create authorization or excuse conduct outside this policy. In particular, this policy does not authorize access to other customers’ accounts or data, data theft, extortion, service disruption, social engineering, persistence, or exploitation beyond the minimum needed to demonstrate an issue safely. It is not a general license to reverse engineer our services, extract or replicate models, distill outputs, train on responses, or reproduce proprietary technology. Any exception to our terms is limited to the minimum activity expressly permitted by this policy; all other restrictions remain in effect.
If you encounter other people’s data or uncertainty about scope, stop testing and contact [email protected]. We may require you to pause or stop specific testing to protect users or systems. If we do, stop that testing immediately and do not resume it without our written authorization. A later request to stop does not withdraw this commitment for earlier activity that complied with the policy. Conduct outside the policy remains subject to applicable law and our terms, and we reserve our rights concerning that conduct.
This policy concerns only permissions and claims Evokoa controls. It does not authorize testing of third-party systems, bind third parties or authorities, or provide immunity from applicable law. If an activity is not clearly permitted, obtain our written authorization before proceeding.
06
Handling your report
We use report details to investigate, communicate with you, and address the issue. Share only information necessary for that work. We may involve service providers or affected parties when needed to resolve the report, subject to applicable privacy obligations. For questions about a report, contact [email protected].