generated: '2026-08-26' method: searched source: https://www.preveil.com/vulnerability-disclosure-policy/ name: PreVeil Vulnerability Disclosure Policy policy_url: https://www.preveil.com/vulnerability-disclosure-policy/ contact: security@preveil.com security_txt: null bug_bounty: false bug_bounty_platform: null safe_harbor: true safe_harbor_note: >- The policy states PreVeil will not initiate or recommend law enforcement or civil action against researchers whose activity stays within the stated restrictions and guidelines. timelines: - stage: acknowledgement target: 3 business days - stage: remediation target: 180 days or less, depending on severity - stage: researcher confidentiality target: up to 90 calendar days after notification out_of_scope: - UI bugs and typos - denial-of-service testing - physical testing - social engineering - brute force attacks evidence: - url: https://www.preveil.com/vulnerability-disclosure-policy/ status: 200 note: Published vulnerability disclosure policy on PreVeil's own domain. - url: https://www.preveil.com/.well-known/security.txt status: 404 note: No security.txt served on the primary host. - url: https://status.preveil.com/.well-known/security.txt status: 200 note: >- Served, but the document is Atlassian's — Canonical points at www.atlassian.com/.well-known/security.txt and the contact is security@atlassian.com. It belongs to the hosted Statuspage product, not to PreVeil, so it is NOT credited as a PreVeil security.txt.