DERIVEE.IO

Responsible Disclosure

If you’ve found a security issue in Derivee’s own systems — this website, our infrastructure, or any Derivee-operated service — we want to know about it, and we’ll work with you in good faith to fix it.

What to do: send details to the security contact listed in the site footer, including steps to reproduce the issue. Please avoid accessing, modifying, or deleting data beyond what’s necessary to demonstrate the issue, and avoid any action that could degrade service for other users.

What to expect: we’ll acknowledge your report and keep you updated as we investigate and remediate. We won’t pursue legal action against good-faith security research conducted under this policy.

This policy covers Derivee’s own systems only — vulnerabilities found during an authorized client engagement should be reported through that engagement’s agreed rules of engagement instead.