About Cahaves
Reporting a vulnerability.
How to report a vulnerability and what we do when you do. A disclosure policy is only useful if it says what happens after the report, so this one does.
- Version
- 0.1
- Effective from
- 2026-08-25
Where to send it
Email security@cahaves.com. Include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps more than a scanner output.
What we do
We acknowledge the report before we have a fix, so you are not left wondering whether it arrived. We tell you what we assess the severity to be and why. We tell you when it is fixed, and we credit you if you want to be credited.
What we ask
Give us a reasonable window to fix the issue before disclosing it publicly. Do not access, modify or delete data belonging to anyone else while testing. Do not run denial-of-service tests or automated scans that degrade the service for other people.
Scope
This site, the three product services, and any subdomain of cahaves.com. Reports about third-party services we merely use should go to that third party.
No bounty programme yet
There is no paid bounty at present. Saying so plainly is better than leaving it ambiguous and disappointing you after the work.