Vulnerability Disclosure Programme Policy
Evercam takes the security of our products, our customers' data and our infrastructure seriously. We value the work of security researchers and members of the public who help us keep our systems safe.
This policy explains how to report a security vulnerability to us, what you can expect from us in return, and the boundaries within which we ask you to operate.
Scope
In scope: The following assets are in scope for testing and reporting:
“evercam.com” and its subdomains owned and operated by Evercam,
the Evercam web application and customer dashboard,
the Evercam public and customer-facing APIs,
Evercam mobile applications published under the Evercam name,
Evercam-developed camera hardware, gateways and firmware, where you own the device being tested.
Out of scope: The following are out of scope, and you must not test them:
Third-party services, platforms and vendors we use (report issues directly to the relevant vendor),
Systems, devices or accounts belonging to Evercam customers or other users, data centres or personnel,
Social engineering of any kind, including phishing and vishing of staff or customers,
Denial-of-service or volumetric testing, and any testing that degrades service availability,
Spam or high-volume automated scanning without manual validation of findings,
Findings we generally do not treat as vulnerabilities,
Reports limited to the following are normally closed as informational unless you can demonstrate a concrete security impact:
Missing security headers or cookie flags without a demonstrated exploit,
Missing SPF, DKIM or DMARC records on non-email domains,
Clickjacking on pages with no sensitive actions,
Self-XSS and issues requiring unlikely user interaction or a previously compromised device,
Version or banner disclosure without a working exploit,
Rate-limiting or brute-force reports on non-sensitive endpoints,
Output of automated scanners submitted without validation,
Vulnerabilities affecting only outdated or unsupported browsers.
Rules of engagement
When researching, you must:
Make every effort to avoid privacy violations, data destruction and disruption to our services or customers,
Only use accounts that you own or that we have provided to you for testing,
Access only the minimum amount of data necessary to demonstrate the vulnerability,
Do not download, copy, modify, retain or share personal data or customer content,
Stop testing and report immediately if you encounter personal data, customer data or credentials,
Not use a vulnerability to pivot into other systems, establish persistence, or access further data
Not publicly disclose the vulnerability, or share details with third parties, before we have had a reasonable opportunity to fix it.
How to report
Please send your report to: t [compliance@evercam.io]
A good report includes:
A clear description of the vulnerability and the affected asset (URL, endpoint, application or device and version),
Step-by-step instructions to reproduce the issue,
A proof of concept, such as screenshots, requests and responses, or a short video,
Your assessment of the potential impact,
Any relevant tools, payloads or configuration used,
Your preferred contact details and how you would like to be credited, if at all
Reports may be submitted anonymously, but we will not be able to ask follow-up questions or credit you.
Please do not include real personal data or customer data in your report. Redact it where possible.
What you can expect from us
Stage Our commitment:
Acknowledgement Within [3] business days of receipt
Initial triage and assessment Within [10] business days
Status updates, At least every [30] days until resolution
Resolution Remediation timelines depend on severity and complexity.
Closure: We will tell you when the issue is resolved and, where possible, give you the opportunity to verify the fix. We will treat your report and your identity as confidential and will not share your personal details outside Evercam without your permission, unless required by law.
Safe harbour
Evercam considers security research conducted in accordance with this policy to be authorised. If you make a good-faith effort to comply with this policy, then:
We will not initiate or support legal action against you for accidental or good-faith violations of this policy, including claims under the Irish Criminal Justice (Offences Relating to Information Systems) Act 2017 or equivalent laws.
We will not initiate or support claims against you for circumvention of technical protection measures or breach of our terms of service, to the extent your research is within the scope of this policy. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make it known that your actions were authorised.
This safe harbour applies only to Evercam's own systems. We cannot authorise testing of third-party systems or bind third parties, and you remain responsible for complying with applicable law. Activity that is clearly outside this policy, or that is malicious, extortionate or causes harm, is not covered. If in doubt about whether something is permitted, contact us before you proceed.
Coordinated disclosure
We ask that you give us a reasonable opportunity to investigate and fix a vulnerability before you disclose it publicly.
Our default disclosure window is [90] days from the date we acknowledge your report. If we need more time because of complexity or dependencies, we will explain why and agree a revised timeline with you, If a fix is released sooner, we will agree a disclosure date with you Where appropriate we will publish a security advisory and, for vulnerabilities in our products, request a CVE identifier. Please do not publish exploit code, proof-of-concept details or any customer data before disclosure has been agreed.
Recognition:
We do not currently operate a paid bug bounty and do not offer monetary rewards for reports. With your permission, we are happy to acknowledge your contribution and to provide a letter of thanks on request.
Personal data:
If your report involves personal data, Evercam will process the information you provide, such as your name, contact details and technical findings, to assess and respond to your report, in line with our Privacy Policy and applicable data protection law, including the GDPR. Our lawful basis is our legitimate interest in maintaining the security of our systems and services.
Contact our Data Protection contact at [compliance@evercam.io] with any queries.
Created by: Information Security Specialist
Creation date: 07.10.2026
Document approver: Chief Technology Officer