Responsible Disclosure
Volum LLC welcomes good-faith reports that help protect the website and systems it operates.
Scope
This policy covers volum.io and systems operated directly by Volum LLC. It does not cover third-party integrations, public blockchain networks, vendors, service providers, or systems you do not own or have permission to test. If scope is unclear, ask before testing.
Reporting channel
Send reports to info@volum.io. For sensitive reports, request the current PGP public key before transmitting exploit details or personal data. PGP fingerprint: pending publication.
Safe harbor
If you act in good faith, stay within this policy, avoid privacy harm and service disruption, and promptly report findings, Volum LLC intends not to pursue legal action solely for the authorized research described here. This statement does not authorize activity that violates law, affects third parties, or exceeds the stated scope.
What to include in a report
Include a concise summary, affected URL or system, reproduction steps, proof of concept that minimizes harm, expected and observed behavior, impact assessment, relevant timestamps, and a way to contact you. Do not include secrets or personal data unless strictly necessary and securely transmitted.
Coordinated disclosure timeline
We aim to acknowledge valid reports promptly and coordinate remediation in good faith. The default disclosure target is 90 days from validation, but the timeline is negotiable based on severity, exploitability, dependencies, and the time required to protect affected parties.
Recognition
With your permission, Volum LLC may recognize qualifying contributors in a hall-of-thanks. Recognition is discretionary and does not create a right to payment, employment, contract, or public disclosure.
Out-of-scope activities
Do not perform denial-of-service or load testing, social engineering, phishing, physical intrusion, credential stuffing, malware deployment, data exfiltration, testing against third parties, or actions that alter, destroy, disclose, or retain data. Do not access accounts or data that are not your own. Stop testing if you encounter personal data or a material service impact.