Skip to content

Security

Report vulnerabilities through one clear private path.

Use the form below to share the issue, how to reproduce it, and which Sonicverse project is affected.

Private reporting
Reproduction details
Coordinated disclosure

Policy

A simpler security reporting policy.

Everything needed to report responsibly, without making the page harder to scan.

Report privately

Use the form below or email security@sonicverse.tech. Include which Sonicverse project, deployment, or repository is affected, and avoid public issue trackers for security-sensitive reports.

Include the essentials

A strong report covers the issue summary, reproduction steps, impact, and any version, environment, URL, project name, or commit details that help us verify it quickly.

Expect coordinated disclosure

We aim to acknowledge reports within 3 business days, complete initial triage within 7, and share follow-up updates as work progresses. Please do not disclose the issue publicly before coordination.

Before you send

A few practical guardrails.

Use the form on this page or email security@sonicverse.tech.

Avoid accessing, modifying, or retaining other people’s data while testing.

If sensitive data may have been exposed, stop testing and tell us immediately in your report.

Report form

Report a vulnerability.

Tell us what happened, how to reproduce it, and what the impact looks like.

Please report issues in good faith, avoid accessing other people’s data, and include enough detail for us to reproduce and verify the problem safely.

List the sequence, test account context, payloads, and any prerequisites.

Explain what an attacker can achieve and who is affected.

Optional. Include a release number, commit SHA, environment, or URL if known.

We review responsible disclosures carefully and use the details here to reproduce the issue.