Vulnerability Disclosure Policy
Last updated: August 2026
EVE NeuroSystems LLC welcomes reports from security researchers. This policy describes how to report a security vulnerability in our services and what you can expect from us. It is the policy referenced by our security.txt.
How to report
Email security@eveaicore.com with a description of the issue, the affected asset, and steps to reproduce. Please give us a reasonable opportunity to remediate before any public disclosure. We will acknowledge your report, keep you informed of our progress, and coordinate disclosure timing with you.
Scope
In scope: eveaicore.com, evecore.ai, evecore.com, our public chat/demo and file-upload endpoints, and our published SDK packages (PyPI / npm).
Out of scope: third-party services we rely on (e.g., AWS, Stripe, Cloudflare, PyPI/npm, and the CDNs listed on our licenses page); volumetric denial-of-service; social engineering of our staff or customers; and findings that require physical access or a rooted/jailbroken device.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, will not pursue or support legal action against you for it, and will work with you to understand and resolve the issue. Please act in good faith, avoid privacy violations and service degradation, only interact with accounts you own or have permission to test, and do not access, modify, or exfiltrate data that is not yours.
Rewards
We do not currently operate a paid bug-bounty program. We are grateful for responsible disclosures and will credit reporters who wish to be acknowledged.
An independent third-party penetration test is planned but not yet completed; once available, a summary may be shared with qualified customers under NDA — contact security@eveaicore.com.