Legal
Responsible Disclosure
Draft · last updated September 30, 2026
Draft for counsel review. This page contains placeholder language prepared before TAMVEL’s legal entity has been formed. It has not been reviewed or approved by legal counsel, does not constitute legal advice, and will be replaced before commercial launch. Bracketed items are placeholders.
We welcome reports from security researchers and will work with you to understand and resolve issues quickly.
How to report
Email [security contact email] with a description of the issue, steps to reproduce, affected URLs or components, and your assessment of impact. [PGP key to be published.] Please do not include personal data of others.
Scope
- In scope: tamvel.com and its subdomains operated by TAMVEL.
- Out of scope: third-party services we use (report to them directly), denial-of-service, volumetric or spam testing, social engineering, and physical attacks.
Guidelines
- Act in good faith, avoid privacy violations and service degradation, and use only accounts you own.
- Stop and report as soon as you confirm a vulnerability; do not access or retain more data than necessary.
- Give us reasonable time to remediate before public disclosure; we will agree a date with you.
What you can expect
We aim to acknowledge reports within [3] business days and to keep you informed of progress. We do not currently operate a paid bug bounty. [Safe-harbor language to be provided by counsel.]