# Saventra — Vulnerability Disclosure # ISO 27001 A.8.8 / OWASP ASVS V1.14.4 Contact: mailto:saventrai@protonmail.com Expires: 2027-05-21T00:00:00.000Z Encryption: https://saventra.app/.well-known/pgp-key.txt Acknowledgments: https://saventra.app/.well-known/security-acknowledgments.txt Policy: https://saventra.app/security # Preferred Languages: en, ru # Scope: # - saventra.app (PWA) # - API endpoints (when deployed) # - Saventra AI Coach (educational module) # Safe Harbor: # We follow the CDRL coordinated disclosure framework. # Accidental, good-faith security research that follows this policy # will not result in legal action. We request: # 1. Give us reasonable time to respond before disclosure # 2. Do not access, modify, or exfiltrate user data # 3. Report findings promptly after discovery # Recognition: # - Hall of Fame listing on our security page # - Public acknowledgment (at your option) # - Swag for validated findings (TBD)