Legal
Responsible Disclosure Policy
Last updated: September 14, 2026
Data security is a top priority for Invadel, and Invadel believes that working with skilled security researchers can identify weaknesses in any technology.
If you believe you’ve found a security vulnerability in Invadel’s service, please notify us; we will work with you to resolve the issue promptly.
Report a vulnerability
info [at] invadel [dot] comWe aim to acknowledge every report within two business days.
Scope
This policy applies to security vulnerabilities discovered in Invadel’s own internet-facing systems, namely the invadel.com website and its subdomains. It does not cover the systems of our clients: if you have identified an issue in a system you believe belongs to an Invadel client, please report it to us and do not test further, and we will route it appropriately.
Safe harbor
Invadel will not pursue or support legal action against you for security research conducted in good faith and in accordance with this policy. We consider such research to be authorized conduct under the Computer Fraud and Abuse Act and analogous laws, and we will not treat it as a breach of our terms of service. If a third party brings legal action against you for activity that complied with this policy, we will make it known that your actions were authorized. If at any point you are unsure whether an action is consistent with this policy, contact us at info [at] invadel [dot] com before proceeding.
Disclosure policy
- If you believe you’ve discovered a potential vulnerability, please let us know by emailing us at info [at] invadel [dot] com. We aim to acknowledge your email within two business days and will keep you updated as we work toward a fix.
- Provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or a third party.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Invadel service. Please only interact with accounts you own or for which you have explicit permission from the account holder.
Exclusions
While researching, we’d like you to refrain from:
- Distributed Denial of Service (DDoS)
- Spamming
- Social engineering or phishing of Invadel employees or contractors
- Any attacks against Invadel’s physical property or data centers
Thank you for helping to keep Invadel and our users safe!
Vulnerabilities we find in third-party products
During engagements and research, Invadel testers sometimes discover vulnerabilities in commercial or open-source software that is not owned by the client. Findings in a client’s own systems are confidential under the engagement contract and are never published. For third-party software, Invadel follows coordinated disclosure:
- Private report first. We notify the vendor or maintainer through their published security contact as soon as the issue is confirmed, with reproduction steps and our severity assessment, and we ask for an expected fix timeline.
- 90-day window. We publish an advisory at the earliest of: the vendor releasing a fix, 90 days from our initial report, or evidence that the vulnerability is being exploited in the wild. A vendor working on a fix in good faith can ask for an extension, and we will agree to a reasonable one.
- CVE assignment. We request a CVE ID for every confirmed vulnerability so that it can be tracked in vulnerability databases and scanners.
- Publication. Advisories are listed on our Security Advisories page with the affected versions, CVSS score, timeline, and fix status. They describe the issue and how to verify it, without weaponized exploit code. The tester who found the issue is credited with their consent.
Vendors who have received a report from us and want to discuss it can reach the security team at info [at] invadel [dot] com.
Changes
We may revise these guidelines from time to time. The most current version will always be available on our Responsible Disclosure Policy page.
Invadel is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at info [at] invadel [dot] com.
Responsibility
Invadel’s security team is responsible for maintaining and enforcing this policy.