Security Policy & Responsible Disclosure
Effective Date: August 5, 2026
Last Updated: August 5, 2026
Version: 1.0
Velura is committed to protecting the security, privacy, and integrity of our Platform and our users.
We appreciate the efforts of security researchers and members of the security community who responsibly identify and report potential vulnerabilities.
This Policy explains how to report security vulnerabilities responsibly and how Velura responds to security reports.
1. Scope
This Policy applies to security vulnerabilities affecting:
- The Velura website;
- The Velura mobile applications;
- Public APIs;
- Public infrastructure owned or operated by Velura;
- Services that are directly managed by Velura.
This Policy does not apply to third-party services that are outside Velura's control.
2. Responsible Disclosure
If you believe you have discovered a security vulnerability, please report it responsibly.
We ask that you:
- Report vulnerabilities promptly;
- Provide sufficient detail for us to reproduce the issue;
- Allow us a reasonable opportunity to investigate and resolve the issue before publicly disclosing it;
- Avoid actions that could negatively impact users or Platform availability.
We appreciate responsible disclosures that help improve the security of the Platform.
3. Good Faith Research
When conducting security research, please:
- Act in good faith;
- Respect user privacy;
- Avoid disrupting Platform operations;
- Minimize any access to personal information;
- Stop testing immediately if you encounter sensitive user data and report the issue.
We will not pursue legal action against researchers who comply with this Policy and conduct security research responsibly and lawfully.
This statement does not authorize activities that violate applicable law or exceed the scope of this Policy.
4. Activities Not Permitted
The following activities are not authorized under this Policy:
- Accessing another user's account without permission;
- Downloading, copying, or modifying personal information;
- Denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks;
- Social engineering attacks;
- Phishing;
- Physical attacks against infrastructure;
- Malware deployment;
- Ransomware;
- Spam campaigns;
- Extortion;
- Destructive testing;
- Cryptocurrency mining;
- Exploitation of vulnerabilities beyond what is reasonably necessary to demonstrate their existence.
5. What to Include in a Report
Please include as much information as possible, including:
- A description of the vulnerability;
- Steps required to reproduce it;
- The affected URL, endpoint, or feature;
- Screenshots or proof of concept where appropriate;
- The potential impact;
- Any suggested remediation.
Providing complete information helps us investigate more quickly.
6. Our Response
When a valid security report is received, Velura aims to:
- Acknowledge receipt within a reasonable time;
- Investigate the reported issue;
- Assess the severity and impact;
- Prioritize remediation based on risk;
- Keep the reporter informed where appropriate.
Response times may vary depending on the complexity and severity of the issue.
7. Security Practices
Velura employs reasonable technical and organizational safeguards designed to protect the Platform.
These safeguards may include:
- HTTPS encryption;
- Secure authentication;
- Access controls;
- Security monitoring;
- Logging;
- Regular software updates;
- Infrastructure hardening;
- Backup and disaster recovery procedures.
No security measure can eliminate all risk, and no Platform can guarantee absolute security.
8. Bug Bounty
Velura does not currently operate a public bug bounty program.
Responsible disclosures are appreciated, but submission of a vulnerability report does not create an entitlement to financial compensation.
Velura may choose to recognize researchers at its sole discretion.
9. Changes to This Policy
Velura may update this Security Policy from time to time.
When material changes are made, the "Last Updated" date at the beginning of this document will be updated.
Continued use of the Platform after changes become effective constitutes acceptance of the revised Policy.
10. Contact
Security reports and questions regarding this Policy may be sent to:
Velura
Website: https://velura.quiksolve.online
Security Email: security@quiksolve.online
Support Email: support@quiksolve.online
Legal Email: legal@quiksolve.online
Please do not submit security vulnerabilities through public forums or social media.
Velura appreciates the efforts of security researchers who help us improve the security and reliability of the Platform through responsible disclosure.