VOLUM
Platform Certificate Compliance Technology VLM Whitepaper
Request access
Legal Center / Security

Responsible Disclosure

LAST UPDATED: 14 AUG 2026
VERSION: 1.0
APPLICABLE ENTITY: VOLUM LLC, WYOMING, USA

Volum LLC welcomes good-faith reports that help protect the website and systems it operates.

  1. Scope

    This policy covers volum.io and systems operated directly by Volum LLC. It does not cover third-party integrations, public blockchain networks, vendors, service providers, or systems you do not own or have permission to test. If scope is unclear, ask before testing.

  2. Reporting channel

    Send reports to info@volum.io. For sensitive reports, request the current PGP public key before transmitting exploit details or personal data. PGP fingerprint: pending publication.

  3. Safe harbor

    If you act in good faith, stay within this policy, avoid privacy harm and service disruption, and promptly report findings, Volum LLC intends not to pursue legal action solely for the authorized research described here. This statement does not authorize activity that violates law, affects third parties, or exceeds the stated scope.

  4. What to include in a report

    Include a concise summary, affected URL or system, reproduction steps, proof of concept that minimizes harm, expected and observed behavior, impact assessment, relevant timestamps, and a way to contact you. Do not include secrets or personal data unless strictly necessary and securely transmitted.

  5. Coordinated disclosure timeline

    We aim to acknowledge valid reports promptly and coordinate remediation in good faith. The default disclosure target is 90 days from validation, but the timeline is negotiable based on severity, exploitability, dependencies, and the time required to protect affected parties.

  6. Recognition

    With your permission, Volum LLC may recognize qualifying contributors in a hall-of-thanks. Recognition is discretionary and does not create a right to payment, employment, contract, or public disclosure.

  7. Out-of-scope activities

    Do not perform denial-of-service or load testing, social engineering, phishing, physical intrusion, credential stuffing, malware deployment, data exfiltration, testing against third parties, or actions that alter, destroy, disclose, or retain data. Do not access accounts or data that are not your own. Stop testing if you encounter personal data or a material service impact.

VOLUM

Verifiable origin infrastructure for regulated global trade. Distributed protocol for authenticated provenance.

Applicable entity
Volum LLC
Wyoming, USA
Patent licensor
Bengala Technologies LLC
US Patent 11,522,690 B2
Platform
Overview Certificate of Origin Technology VLM token
Compliance
Regulatory map Whitepaper 2019 legal memo
Legal Center
All policies Terms of Use Privacy Policy Cookie Policy Risk Disclosures VLM Disclaimer Jurisdictional Intellectual Property Accessibility Responsible Disclosure
Contact
Request access info@volum.io
© 2026 Volum LLC. All rights reserved. TermsPrivacyCookies www.volum.io
Cookies & preferences

Volum uses strictly necessary cookies for session security. Analytics are disabled by default. You can review categories and set preferences at any time.

Cookie policy