Report a vulnerability in Eresus Guard.
Send a private report to security@eresussec.com. Do not open a public issue or send customer data.
What to include
- The affected Eresus Guard surface, route, or component
- Minimal reproduction steps and the security impact
- The version or hosted URL you tested
- Sanitized request, response, log, or screenshot evidence
Research boundaries
Test only systems and accounts you are authorized to use. Do not access another customer's data, disrupt availability, use social engineering, or scan third-party targets through Eresus Guard.
Response process
We acknowledge reports within 48 hours and provide an initial resolution timeline within seven business days. Fix and disclosure timing depends on severity, exploitability, and affected deployments.
Bug bounty status
This is a coordinated disclosure channel, not a public paid bug bounty. No reward is promised. If a public bounty opens, its scope, safe-harbor terms, and reward table will be published here before testing begins.
Keep the first report private.
Email security@eresussec.com with the smallest evidence set that proves the issue.