Security / Abuse

Report security issues or abuse privately.

Use this page for suspected vulnerabilities, spam, phishing, impersonation, malicious files, account compromise, privacy abuse, or unauthorized access.

This page is an intake and reporting guide, not a bug bounty program, safe-harbor promise, legal waiver, or authorization to test production systems without written approval.

Reporting guidelines

  • Do not publicly disclose a vulnerability before ChemVault has had a reasonable opportunity to investigate.
  • Do not attack real users, access data that is not yours, disrupt service, or attempt destructive testing.
  • Do not upload malware, exploit payloads, malicious files, or illegal content.
  • Do not include passwords, API keys, private keys, recovery codes, tokens, or other secrets in ordinary reports.
  • Provide the affected URL, steps to reproduce, impact, and any non-sensitive evidence.
  • High-risk issues should be reported privately through the form or contact email.

Abuse categories

Report spam, phishing, sender impersonation, malicious attachments, file abuse, account compromise, unauthorized admin access, exposed secrets, or privacy concerns.

Response targets

We aim to acknowledge critical reports within 24 hours, high-severity reports within two business days, medium reports within five business days, and low-severity reports within ten business days. These are operational targets, not guarantees.

Contact

Private intake: forms.chemvault.science/security-report. Fallback email: contact@chemvault.science.

Submission does not create a bug bounty, safe-harbor promise, legal waiver, or authorization to test production systems without written approval.