All policies

Trust & security

Responsible Disclosure Policy

Version 1.0Effective July 31, 2026Updated 2026-06-28

Summary

We welcome good-faith security research. If you find a vulnerability in Evigate, report it privately to security@logethos.com and give us a reasonable chance to fix it before public disclosure. Stay within scope, don't access other people's data, and don't degrade the service; do that, and we won't pursue legal action against your good-faith research.


1. Scope

In scope: the Evigate hosted application and API at our production domains (logethos.com and its app/API subdomains) and the official Docker images for self-hosted deployment. If you are unsure whether something is in scope, ask first at security@logethos.com.

2. How to report

Email security@logethos.com with:

  • A clear description of the issue and its potential impact.
  • Step-by-step reproduction details (and a minimal proof-of-concept if possible).
  • The affected URL/endpoint, parameters, and any relevant request/response data

    with secrets and other people's data redacted.

Please encrypt sensitive details if you can, and avoid including real customer data in your report.

3. Rules of engagement

Do:

  • Test only against your own accounts and data.
  • Stop as soon as you confirm a vulnerability and report it.
  • Keep details confidential until we've had a reasonable time to remediate

    (we suggest 90 days as a coordinated-disclosure window, sooner by mutual agreement).

Do not:

  • Access, modify, or exfiltrate data that isn't yours, or attempt to break tenant

    or project isolation against real tenants.

  • Run denial-of-service or volumetric/load tests, spam, or social-engineering /

    phishing against our staff or users.

  • Use automated scanners that generate high-volume traffic against production

    without prior coordination.

  • Publicly disclose before we've remediated or before the agreed window.

4. Out of scope

Typically not eligible (unless you can show real, demonstrable impact):

  • Missing security headers or cookie flags without a concrete exploit.
  • Rate-limiting thresholds, self-XSS, clickjacking on non-sensitive pages.
  • Reports from automated tools without a working proof-of-concept.
  • Vulnerabilities in third-party providers (report those to the provider; see

    Subprocessors).

  • Issues in a customer's self-hosted deployment caused by the customer's own

    configuration or environment.

5. Our commitments

  • Acknowledge your report within [DISCLOSURE_ACK_DAYS] business days.
  • Provide a triage assessment and keep you updated on remediation.
  • Work in good faith to fix valid issues promptly, prioritized by severity.
  • Not pursue legal action for research conducted in line with this policy.

6. Safe harbor

We consider security research conducted in accordance with this policy to be authorized, will not initiate legal action against you for it, and will work with you if a third party brings action over your good-faith, in-scope research. Activity that violates the Acceptable Use Policy or the rules above is not authorized.

7. Recognition

We're happy to credit researchers who report valid issues, with your permission.

*Operator note:* we run no paid bug-bounty program at this time. If you introduce one, document rewards and scope here.


*Effective date: July 31, 2026 · Last updated: 2026-06-28 · Version 1.0*