Vulnerability Disclosure Policy

Last updated: 11 August 2026

Distributary operates heldaway.ai, evmgmt.ai and distributary.io (together, the "Services"). We take the security of our systems and our customers' data seriously and we welcome reports from security researchers acting in good faith. This policy explains how to report a vulnerability to us, what you can expect in return, and the rules for testing.

This is a coordinated disclosure policy, not a bug bounty program. We do not offer monetary rewards. See "Rewards" below.

Scope

The following systems are in scope:

  • heldaway.ai and its subdomains
  • evmgmt.ai and its subdomains
  • distributary.io and its subdomains
  • work.heldaway.ai (the application)

Out of scope

The following are explicitly out of scope. Reports limited to these, without a demonstrated, realistic security impact, will be closed without further action:

  • Denial of service (DoS/DDoS), volumetric, or resource-exhaustion testing
  • Social engineering, phishing, or physical attacks against our staff, users, or offices
  • Reports from automated scanners without a working proof of concept
  • Missing security headers (CSP, HSTS, etc.) with no demonstrated exploit
  • Missing or misconfigured SPF, DKIM, or DMARC records
  • TLS/SSL configuration weaknesses (cipher suites, versions) without a working exploit
  • Software or framework version disclosure without a linked, exploitable vulnerability
  • Self-XSS, or issues requiring an already-compromised device or browser
  • Clickjacking on pages with no sensitive state-changing actions
  • Rate-limiting or brute-force findings without demonstrated impact
  • Best-practice or informational findings with no security impact

How to report

Email security@heldaway.ai. Please include:

  • The affected Service, URL, and component
  • A clear description of the issue and its security impact
  • Step-by-step reproduction details, including a proof of concept where possible
  • Any relevant logs, requests, or screenshots

Please report one issue per email, and give us a reasonable opportunity to respond before disclosing to anyone else.

What to expect

  • We will acknowledge your report within 10 business days.
  • We will work to validate the report and keep you informed of our progress.
  • We ask that you keep the details of any vulnerability confidential until we have had a reasonable opportunity to remediate it.

Rules of engagement

When researching, we ask that you:

  • Only test against systems listed in scope above.
  • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our Services.
  • Do not access, modify, or exfiltrate data that does not belong to you. Use only test accounts you own.
  • Stop testing and notify us immediately if you encounter customer data.
  • Do not use automated scanning at a volume that could degrade the Services.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you related to your research. To the extent permitted by applicable law, we waive any relevant claims against you for good-faith security research conducted in line with this policy. This policy does not authorise action inconsistent with applicable law, and it does not bind any third party.

Rewards

We do not operate a bug bounty program and do not offer monetary rewards, gifts, or other compensation for reports. By submitting a report you agree that you are not entitled to, and waive any claim to, compensation for the submission. We are grateful for responsible disclosure and are happy to acknowledge researchers who wish to be credited once an issue is resolved.

Security contact: security@heldaway.ai ยท security.txt