Document the issue
Capture the affected page, endpoint, account role, browser, timestamps, and the exact behavior you observed.
If you believe you found a vulnerability in Velrin, send a clear report so we can reproduce, assess, and remediate the issue without disrupting production or exposing user data.
Numbered actions, affected URL, role, and environment.
What data, permission, workflow, or user action is affected.
Screenshots, request IDs, timestamps, logs, or console errors.
No public disclosure until the issue has been reviewed and resolved.
A strong report should help us reproduce the issue quickly, understand the business impact, and identify the safest remediation path.
Capture the affected page, endpoint, account role, browser, timestamps, and the exact behavior you observed.
Describe what an attacker could access, change, bypass, or disrupt if the issue were exploited.
Provide screenshots, redacted requests, console errors, or logs without exposing unrelated user data.
Give us time to triage, fix, and validate before discussing the issue publicly.
Security research should be limited, targeted, and non-destructive. Test only against accounts, workspaces, and data you own or are explicitly authorized to use.
We follow a clear intake path so vulnerability reports stay structured, accountable, and reviewable.
We confirm receipt and ask for clarifying details if the report needs more context.
We reproduce the issue, assess severity, and identify the affected product area.
We prepare and validate the fix in a controlled way before release.
We confirm the vulnerability is resolved and close the report with final notes.
You do not need to use this format exactly, but these fields help us move faster and avoid back-and-forth.
Subject: Vulnerability Report — Velrin
Summary:
Affected area:
Account role used:
Steps to reproduce:
Expected result:
Actual result:
Potential impact:
Evidence:
Suggested remediation, if any:
Disclosure coordination notes:
Send your report to security@velrin.com with enough detail to reproduce safely. For general product or access questions, use the contact page instead.