Responsible Disclosure
How to report a vulnerability in delveIn itself.
Last updated 2026-02-01
Scope
In-scope: the delveIn web application, its APIs, authentication and payment flows, entitlement enforcement and download delivery. Out-of-scope: social engineering, physical attacks, denial of service, and spam.
How to report
Email security@delvein.dev with reproduction steps, impact and any supporting evidence. Do not access, modify or exfiltrate data that is not yours. Automated scanning against production is not permitted without prior written agreement.
Our commitment
We acknowledge reports within 2 business days, provide a status update at least every 5 business days, and credit researchers in our hall of thanks once a fix is released (unless you prefer to remain anonymous).
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, will not pursue legal action, and will work with you to understand and resolve the issue quickly.
Questions about this document? Email support@delvein.dev. Related pages: Acceptable Use · Terms
