Trust & security
Responsible Disclosure Policy
Summary
We welcome good-faith security research. If you find a vulnerability in Evigate, report it privately to security@logethos.com and give us a reasonable chance to fix it before public disclosure. Stay within scope, don't access other people's data, and don't degrade the service; do that, and we won't pursue legal action against your good-faith research.
1. Scope
In scope: the Evigate hosted application and API at our production domains (logethos.com and its app/API subdomains) and the official Docker images for self-hosted deployment. If you are unsure whether something is in scope, ask first at security@logethos.com.
2. How to report
Email security@logethos.com with:
- A clear description of the issue and its potential impact.
- Step-by-step reproduction details (and a minimal proof-of-concept if possible).
- The affected URL/endpoint, parameters, and any relevant request/response data
with secrets and other people's data redacted.
Please encrypt sensitive details if you can, and avoid including real customer data in your report.
3. Rules of engagement
Do:
- Test only against your own accounts and data.
- Stop as soon as you confirm a vulnerability and report it.
- Keep details confidential until we've had a reasonable time to remediate
(we suggest 90 days as a coordinated-disclosure window, sooner by mutual agreement).
Do not:
- Access, modify, or exfiltrate data that isn't yours, or attempt to break tenant
or project isolation against real tenants.
- Run denial-of-service or volumetric/load tests, spam, or social-engineering /
phishing against our staff or users.
- Use automated scanners that generate high-volume traffic against production
without prior coordination.
- Publicly disclose before we've remediated or before the agreed window.
4. Out of scope
Typically not eligible (unless you can show real, demonstrable impact):
- Missing security headers or cookie flags without a concrete exploit.
- Rate-limiting thresholds, self-XSS, clickjacking on non-sensitive pages.
- Reports from automated tools without a working proof-of-concept.
- Vulnerabilities in third-party providers (report those to the provider; see
- Issues in a customer's self-hosted deployment caused by the customer's own
configuration or environment.
5. Our commitments
- Acknowledge your report within [DISCLOSURE_ACK_DAYS] business days.
- Provide a triage assessment and keep you updated on remediation.
- Work in good faith to fix valid issues promptly, prioritized by severity.
- Not pursue legal action for research conducted in line with this policy.
6. Safe harbor
We consider security research conducted in accordance with this policy to be authorized, will not initiate legal action against you for it, and will work with you if a third party brings action over your good-faith, in-scope research. Activity that violates the Acceptable Use Policy or the rules above is not authorized.
7. Recognition
We're happy to credit researchers who report valid issues, with your permission.
*Operator note:* we run no paid bug-bounty program at this time. If you introduce one, document rewards and scope here.
*Effective date: July 31, 2026 · Last updated: 2026-06-28 · Version 1.0*