Report a Vulnerability
Effective date: July 3, 2026
Volana values the work of independent security researchers. If you've found a security issue in our product, this page explains how to report it and what to expect from us in return.
How to Report
Email security@volana.app with details of the issue. We read every report and will acknowledge receipt as soon as we can.
What to Include
- Steps to reproduce the issue, as detailed as possible.
- The impact of the issue, what an attacker could do with it.
- The affected URL, endpoint, or feature.
- Any proof-of-concept code, screenshots, or logs that help us confirm and reproduce the issue.
Safe Harbor
We will not pursue legal action against researchers who report a vulnerability in good faith and follow this policy. To qualify:
- Avoid privacy violations, including accessing or modifying data that isn't your own.
- Avoid destroying data or degrading the availability of our service, including through denial-of-service testing.
- Give us reasonable time to investigate and fix the issue before any public disclosure.
- Only interact with accounts you own or have explicit permission to test.
If you follow these guidelines, we consider your research authorized and will work with you to understand and resolve the issue quickly.
Machine-Readable Policy
A machine-readable version of this policy, in the standard RFC 9116 format, is published at /.well-known/security.txt.