Security research
Last updated: August 23, 2026
Controls and boundaries
State remains inspectable
Evnao values security research. We encourage responsible disclosure of vulnerabilities in our service so we can fix them. We will not initiate legal action against security researchers who follow this policy in good faith.
This policy covers the Evnao production platforms, including API endpoints and customer-facing apps. It does not authorize attacks on third-party components (e.g. payment processor, LLM providers, social media integrations). It does not authorize testing the underlying LLM models or networks beyond normal use.
Researchers may test any feature of the Evnao service, but must avoid:
Send reports via email to security@evnao.com. Provide: steps to reproduce, affected URLs, and proof-of-concept. Include contact information if you would like updates or public recognition after remediation.
Evnao will not pursue legal action against researchers who adhere to this policy in good faith, including the testing guidelines and scope described above. This safe harbor does not extend to activities that violate law, access other customers' data, or cause harm to the Service or its users. Evnao reserves the right to take action against willful or malicious violations.
Report issues to security@evnao.com. For non-vulnerability inquiries, see our Contact page.