About Cahaves

Reporting a vulnerability.

How to report a vulnerability and what we do when you do. A disclosure policy is only useful if it says what happens after the report, so this one does.


Version
0.1
Effective from
2026-08-25

Where to send it

Email security@cahaves.com. Include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps more than a scanner output.

What we do

We acknowledge the report before we have a fix, so you are not left wondering whether it arrived. We tell you what we assess the severity to be and why. We tell you when it is fixed, and we credit you if you want to be credited.

What we ask

Give us a reasonable window to fix the issue before disclosing it publicly. Do not access, modify or delete data belonging to anyone else while testing. Do not run denial-of-service tests or automated scans that degrade the service for other people.

Scope

This site, the three product services, and any subdomain of cahaves.com. Reports about third-party services we merely use should go to that third party.

No bounty programme yet

There is no paid bounty at present. Saying so plainly is better than leaving it ambiguous and disappointing you after the work.